skills-sync

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose matches syncing skills, but the footprint is high-risk because it ingests arbitrary remote skill repositories, auto-installs tooling, and converts untrusted SKILL.md content into agent-consumed Cursor rules. No clear evidence of credential theft or overt malware, but the transitive trust and prompt-injection surface make this a high security-risk skill.

Confidence: 90%Severity: 84%
Audit Metadata
Analyzed At
Mar 13, 2026, 09:51 PM
Package URL
pkg:socket/skills-sh/sfc-gh-dflippo%2Fsnowflake-dbt-demo%2Fskills-sync%2F@61073ce1bf4b46e2b143026ac6e05bbb0ab93695