extend

Warn

Audited by Socket on Mar 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose matches marketplace delegation, but the skill expands trust to an unverified third-party CLI and external specialists, with mutable installation and outbound task sharing. The behavior is coherent with its purpose, yet install provenance is unclear and data leaves the local environment for paid third-party execution, so risk is medium-high rather than benign.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
Mar 16, 2026, 12:31 AM
Package URL
pkg:socket/skills-sh/openstall-ai%2Fagent-marketplace%2Fextend%2F@98021e7e8130b89f391c87080d8efba1385f4f81