agentskills-io

Fail

Audited by Socket on Feb 21, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Code execution from unpinned remote source (uvx/pipx + git URL) Report 1 is the strongest baseline, accurately reflecting the repository's purpose and operational workflow. The improved assessment adds concrete security-oriented observations about external tooling and configuration pitfalls, delivering a more complete, actionable evaluation while maintaining benign default risk posture. LLM verification: The document is legitimate documentation for creating and validating agent skills and is not itself malicious. However, it instructs users to install and execute remote code from a git+https URL without pinning or integrity checks. This download-and-execute pattern is a material supply-chain risk: if the remote repository or its dependencies are compromised, arbitrary code could run on users' machines. Recommend replacing unpinned installation commands with pinned tags/commit hashes, providing c

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 21, 2026, 01:34 AM
Package URL
pkg:socket/skills-sh/openclaw%2Fskills%2Fagentskills-io%2F@9babd073022e1be19e7e7e312ac10ae1da46fd8e