skill-builder

Warn

Audited by Socket on Apr 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's core behavior is mostly aligned with a skill scaffolding/management purpose, but it also instructs the agent to clone a personal GitHub repo, execute local install scripts, and install/manage other skills transitively. There is no clear credential theft or exfiltration, so this is not malicious, but the combination of repo-trust dependency, command execution, persistent installation, and transitive skill loading makes it medium-high risk.

Confidence: 90%Severity: 74%
Audit Metadata
Analyzed At
Apr 7, 2026, 07:37 PM
Package URL
pkg:socket/skills-sh/shetengteng%2Fskillix-hub%2Fskill-builder%2F@a353a0f63f72d7f0a5723afd3359cd4ee1326658