raw-github
Fail
Audited by Socket on Apr 20, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
MALICIOUS. The skill’s stated purpose is effectively to run an attacker-controlled raw GitHub script through curl|bash. Its actual footprint is fundamentally incompatible with safe skill behavior: untrusted remote content, mutable branch source, no verification, and immediate code execution. This is a classic social-engineering download/execute pattern and should not be downgraded.
Confidence: 98%Severity: 99%
Audit Metadata