skill-library

Warn

Audited by Socket on Apr 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent as a package installer, but its core behavior is high-trust transitive installation of agent packages from a personal GitHub repository using mutable remote content and executable utility installs. No clear credential theft or exfiltration is shown, but the supply-chain and inherited-permission risks are substantial.

Confidence: 87%Severity: 81%
Audit Metadata
Analyzed At
Apr 12, 2026, 06:27 AM
Package URL
pkg:socket/skills-sh/Mathews-Tom%2Farmory%2Fskill-library%2F@832ef0ce5ce1d083f30a1199d8a486c43561a8ad