discover-skills
Warn
Audited by Socket on May 7, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is broadly aligned with its stated purpose and does not auto-install, but its main function is to induce transitive skill installation via runtime-resolved `npx skills add` commands. Official ecosystem evidence lowers concern from malicious to moderate supply-chain/trust risk, especially for third-party repos and external catalogs.
Confidence: 84%Severity: 58%
Audit Metadata