find-skills

Fail

Audited by Socket on Feb 27, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The fragment is a coherent, benign documentation asset that describes how to discover and install open agent skills via a CLI. It does not itself perform downloads, read credentials, or exfiltrate data. In isolation, it poses minimal security risk; however, as a guide to install third-party skills, it relies on users selecting external packages, which means the downstream risk depends on the integrity of those external skills and registries. Overall, the footprint is proportionate to its stated purpose, with no anomalous or malicious behavior detected in the fragment itself.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 27, 2026, 02:26 PM
Package URL
pkg:socket/skills-sh/phrazzld%2Fclaude-config%2Ffind-skills%2F@c2f31172b6f256272305a5e6e7228b258446899f