skill-installer

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: the installer is internally consistent and uses official GitHub/OpenAI sources for curated content, but its main function is high-risk transitive skill installation. The largest concern is allowing arbitrary GitHub repos/private repos to place new skill instructions into the agent's trusted skill directory, not direct credential theft or off-platform exfiltration.

Confidence: 87%Severity: 74%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:36 PM
Package URL
pkg:socket/skills-sh/oldwinter%2Fskills%2Fskill-installer%2F@97354812183c05f12316612934f97fa5b2970585