third-party-skills

Warn

Audited by Socket on Mar 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is internally consistent as a third-party catalog, but its main purpose is to install other unreviewed skills from external publishers. The official CLI provenance lowers concern versus arbitrary download-execute, yet the transitive trust chain, unpinned `npx` execution, and bulk installation behavior make this a meaningful supply-chain risk.

Confidence: 86%Severity: 68%
Audit Metadata
Analyzed At
Mar 24, 2026, 12:07 PM
Package URL
pkg:socket/skills-sh/sales-skills%2Fsales%2Fthird-party-skills%2F@0c7cd9a5db8d81e2281e6c0e5331936cee946be6