.agents

Fail

Audited by Socket on Mar 14, 2026

1 alert found:

Malware
MalwareHIGH
skills/find-skills/SKILL.md

SUSPICIOUS: the skill is internally consistent and uses an apparently official CLI, but its main purpose is to discover and install other skills, including third-party sources. That transitive installation behavior is a meaningful security risk even without direct malicious behavior or credential theft in this skill itself.

Confidence: 88%Severity: 74%
Audit Metadata
Analyzed At
Mar 14, 2026, 09:23 AM
Package URL
pkg:socket/skills-sh/rabbit-ivan%2Fivan-skills%2Fagents%2F@31f03822815e4096e925eb0cbee371bb181c9ce7