add-skill

Warn

Audited by Socket on Apr 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill is coherent with its stated purpose, but that purpose is inherently high-risk because it installs other skills from arbitrary GitHub repositories into the agent's trusted workspace. Data flow to GitHub is consistent and there is no clear exfiltration indicator, yet the transitive trust chain and GITHUB_TOKEN use make this a significant supply-chain risk.

Confidence: 87%Severity: 78%
Audit Metadata
Analyzed At
Apr 25, 2026, 01:32 PM
Package URL
pkg:socket/skills-sh/openhands%2Fskills%2Fadd-skill%2F@4c0aadf913c06b66a8d586e18c8bea2e562ccbe1