mthds-install

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's purpose matches installation, but its footprint includes multi-stage trust delegation: npm CLI install, arbitrary GitHub package install, optional transitive skill installation, and possible runtime setup. Those capabilities are coherent with an installer skill, yet the lack of provenance checks, pinning, or verification for GitHub-installed methods/skills makes the overall risk medium to high rather than benign.

Confidence: 84%Severity: 74%
Audit Metadata
Analyzed At
Mar 14, 2026, 04:23 AM
Package URL
pkg:socket/skills-sh/mthds-ai%2Fskills%2Fmthds-install%2F@8f1b8c59ae94a75fcea4e6d0ddda116e9043fa51