secondme-external-skill-catalog

Warn

Audited by Socket on Mar 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's purpose matches its behavior, and endpoints appear first-party to MindOS, so this is not confirmed malware. But it is materially risky because it reads a token, downloads remote skill bundles, and installs prompt-injection files exactly as returned with no integrity verification or review, creating a high transitive-trust and prompt-injection exposure.

Confidence: 88%Severity: 74%
Audit Metadata
Analyzed At
Mar 16, 2026, 03:42 AM
Package URL
pkg:socket/skills-sh/Mindverse%2FSecond-Me-Skills%2Fsecondme-external-skill-catalog%2F@3c7014f89a2e5d7959c669e20b9a065451aacb40