curate-a-team-library

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose is coherent, but the skill’s main function is to execute an npm-resolved CLI and install/import additional skills from upstream sources, creating meaningful supply-chain and transitive-trust risk. No clear credential harvesting or exfiltration is present, so this is not confirmed malware.

Confidence: 80%Severity: 68%
Audit Metadata
Analyzed At
Mar 31, 2026, 04:40 PM
Package URL
pkg:socket/skills-sh/skillcreatorai%2Fai-agent-skills%2Fcurate-a-team-library%2F@623d098397f1dec7bcc9688e25e7c4e7fe503a83