curate-a-team-library

Warn

Audited by Socket on Apr 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose is coherent, but the skill’s main function is to execute an npm-resolved CLI and install/import additional skills from upstream sources, creating meaningful supply-chain and transitive-trust risk. No clear credential harvesting or exfiltration is present, so this is not confirmed malware.

Confidence: 80%Severity: 68%
Audit Metadata
Analyzed At
Apr 3, 2026, 04:17 PM
Package URL
pkg:socket/skills-sh/MoizIbnYousaf%2FAi-Agent-Skills%2Fcurate-a-team-library%2F@623d098397f1dec7bcc9688e25e7c4e7fe503a83