remote-skill-test

Warn

Audited by Socket on Apr 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the behavior mostly matches a remote skill-testing purpose, but it achieves that by installing other skills, bypassing SSH host verification, loading remote secrets from interactive shell config, and running OpenCode with permission checks disabled. The footprint is coherent yet disproportionately powerful, so this is not confirmed malware but it is a high-risk orchestration skill.

Confidence: 91%Severity: 86%
Audit Metadata
Analyzed At
Apr 18, 2026, 02:24 AM
Package URL
pkg:socket/skills-sh/panlm%2Fskills%2Fremote-skill-test%2F@b8a2da684da0289ccc30f06a2f29c0dddfe64450