find-skills

Fail

Audited by Socket on Mar 22, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: the skill is coherent with its stated purpose, and the CLI appears official, but its main function is transitive skill installation from broad third-party sources. The use of noninteractive install (`-y`) and expansion of the agent's capabilities/permissions through newly installed skills make this a high-trust workflow that should be treated as risky even without direct malware indicators.

Confidence: 90%Severity: 78%
Audit Metadata
Analyzed At
Mar 22, 2026, 01:14 AM
Package URL
pkg:socket/skills-sh/poteto%2Fnoodle%2Ffind-skills%2F@9238b33cc992365ae531961d2f0b046f11e66498