skillhub-guide

Warn

Audited by Socket on Apr 6, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose and capabilities are mostly aligned, but its main install path depends on an unverified remote pipe-to-shell installer and then encourages transitive installation of additional skills through an external CLI. There is no clear credential harvesting or overt exfiltration, but the install/execution trust model is too weak to treat as benign.

Confidence: 86%Severity: 79%
Audit Metadata
Analyzed At
Apr 6, 2026, 09:44 PM
Package URL
pkg:socket/skills-sh/Peiiii%2Fnextclaw%2Fskillhub-guide%2F@878e542868f500102c32a32a157b7fce36587277