share-a-library

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose and capabilities mostly align, but it combines unpinned third-party CLI execution, public GitHub publishing, and transitive agent-install generation. The main concern is not hidden malware behavior; it is the high-impact trust chain and risk of oversharing local workspace contents through public publication and downstream skill installation.

Confidence: 85%Severity: 72%
Audit Metadata
Analyzed At
Mar 31, 2026, 04:41 PM
Package URL
pkg:socket/skills-sh/skillcreatorai%2Fai-agent-skills%2Fshare-a-library%2F@5435ede0d051b0fdf10f9ca6b1de6d2ecaa566fa