find-skills

Fail

Audited by Socket on Mar 21, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS. The skill's stated purpose matches its behavior, and the CLI appears to be an official ecosystem tool, so this is not outright malicious. However, the skill is inherently high-trust because it directs the agent to discover and install additional third-party skills, including non-interactive global installs, with unpinned runtime execution and no clear integrity verification. The main risk is transitive installation of unreviewed skills that can expand the agent's permissions and behavior.

Confidence: 90%Severity: 76%
Audit Metadata
Analyzed At
Mar 21, 2026, 06:48 PM
Package URL
pkg:socket/skills-sh/lev-os%2Fagents%2Ffind-skills%2F@da9ce882ecdfe5a27a4e63b28ad87227524e0b38