curate-a-team-library
Warn
Audited by Socket on Mar 31, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the stated purpose is coherent, but the skill’s main function is to execute an npm-resolved CLI and install/import additional skills from upstream sources, creating meaningful supply-chain and transitive-trust risk. No clear credential harvesting or exfiltration is present, so this is not confirmed malware.
Confidence: 80%Severity: 68%
Audit Metadata