skill-library
Warn
Audited by Socket on Apr 12, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally consistent as a package installer, but its core behavior is high-trust transitive installation of agent packages from a personal GitHub repository using mutable remote content and executable utility installs. No clear credential theft or exfiltration is shown, but the supply-chain and inherited-permission risks are substantial.
Confidence: 87%Severity: 81%
Audit Metadata