skill-seekers

Warn

Audited by Socket on Mar 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill-seekers description presents a well-scoped tool for transforming docs and code into Claude/Cursor skills with optional AI enhancement and multi-source coordination. There is no evident malicious code or covert credential harvesting in the fragment; however, the architecture entails legitimate data flows to external AI endpoints and skill platforms, which necessitates careful handling of credentials, data minimization, access controls, and explicit user consent. The overall footprint appears coherent with the stated purpose but carries moderate security risk due to external data transmissions and multi-platform integrations that expand the attack surface. Recommend formal threat modeling around data provenance, access scopes, and credential management before broad deployment.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 4, 2026, 07:14 AM
Package URL
pkg:socket/skills-sh/rinbarpen%2Fvibe-coding%2Fskill-seekers%2F@f13fc8e55157b7bc0661e56de4d31d7ec2d28cd7