find-skills

Fail

Audited by Socket on Mar 8, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's stated purpose (discovering and installing third-party skills via skills.sh) is broadly coherent with its described capabilities and workflows. However, the footprint entails notable supply-chain risk and potential for executing unverified remote code, especially during install-time and when integrating external skills. This is amplified by the reliance on external repositories (GitHub, GitLab) and a centralized registry without explicit provenance verification or sandboxing. The risk level is MEDIUM due to third-party installs and remote code execution potential, with notable concerns around supply-chain trust and lack of explicit security controls described. No credentials are explicitly required by the skill itself, but the act of installing external skills could lead to credential exposure if downstream skills request access tokens or keys. Overall, the skill is plausible and useful for its purpose, but should include stronger security measures (verifiable signatures, sandboxed execution, explicit permission prompts, and provenance checks) to be considered robust for production use.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 8, 2026, 03:52 AM
Package URL
pkg:socket/skills-sh/mgiovani%2Fcc-arsenal%2Ffind-skills%2F@293eb1dc44e7e53f34bb8ce2e56f78c4fb6acd23