skill-seekers
Audited by Socket on Mar 4, 2026
1 alert found:
SecurityThe skill-seekers description presents a well-scoped tool for transforming docs and code into Claude/Cursor skills with optional AI enhancement and multi-source coordination. There is no evident malicious code or covert credential harvesting in the fragment; however, the architecture entails legitimate data flows to external AI endpoints and skill platforms, which necessitates careful handling of credentials, data minimization, access controls, and explicit user consent. The overall footprint appears coherent with the stated purpose but carries moderate security risk due to external data transmissions and multi-platform integrations that expand the attack surface. Recommend formal threat modeling around data provenance, access scopes, and credential management before broad deployment.