discover-skills

Warn

Audited by Socket on May 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly aligned with its stated purpose and does not auto-install, but its main function is to induce transitive skill installation via runtime-resolved `npx skills add` commands. Official ecosystem evidence lowers concern from malicious to moderate supply-chain/trust risk, especially for third-party repos and external catalogs.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
May 7, 2026, 05:42 AM
Package URL
pkg:socket/skills-sh/nesnilnehc%2Fai-cortex%2Fdiscover-skills%2F@8f0a6316b0ff41dafba69126fa3beb4a26f74aef