using-toolkit

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core behavior is a dispatcher, but it is overly coercive and expands trust to additional skills by default. The official `npx skills` CLI lowers pure malware concern, yet the skill's main footprint is transitive skill loading and unpinned third-party installation, which is disproportionate for a simple catalog/dispatch helper.

Confidence: 88%Severity: 74%
Audit Metadata
Analyzed At
Apr 2, 2026, 12:45 AM
Package URL
pkg:socket/skills-sh/Pixel-Process-UG%2Fsuperkit-agents%2Fusing-toolkit%2F@c7fcb07209bc60d7a81eaaae349d2a042c45b07d