manage-skills
Warn
Audited by Socket on Mar 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated purpose matches skill management, but its primary capability is installing additional third-party skills through a weakly verified CLI and community/untrusted sources. The main risk is transitive trust and future privilege inheritance, not confirmed malware or direct exfiltration in this file.
Confidence: 85%Severity: 76%
Audit Metadata