auto-update-plugins

Warn

Audited by Socket on Apr 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's purpose matches plugin syncing, but it achieves this by automatically installing and refreshing other agent plugins from GitHub on every session start. That transitive installation model, combined with unpinned remote sources and reduced user review, makes the footprint higher risk than a normal documentation or utility skill.

Confidence: 87%Severity: 83%
Audit Metadata
Analyzed At
Apr 3, 2026, 06:09 PM
Package URL
pkg:socket/skills-sh/richfrem%2Fagent-plugins-skills%2Fauto-update-plugins%2F@a51f1dd10e48919cb970e6292bb1b628cfe90c24