update-installed-skills

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s behavior matches its stated purpose, but that purpose itself is high-trust. It uses a legitimate npm CLI rather than a covert payload, yet it updates other skills from remote sources and can fresh-clone GitHub repos, creating a meaningful transitive supply-chain risk. No clear credential theft, stealth, or malicious exfiltration is present, so this is not malware; it is a medium-risk updater skill that should only be used with trusted upstream skill sources and careful dry-run review.

Confidence: 82%Severity: 64%
Audit Metadata
Analyzed At
Mar 31, 2026, 04:41 PM
Package URL
pkg:socket/skills-sh/skillcreatorai%2Fai-agent-skills%2Fupdate-installed-skills%2F@d9edcea4dca17386d4ed8bf55a17fc8a824a7b4c