plugins

Warn

Audited by Socket on May 5, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is coherent as an extension manager, but its footprint is high-risk because it installs and republishes third-party skills/plugins from broad sources into multiple agent ecosystems without strong provenance controls. No direct credential theft or clear exfiltration is shown, but transitive skill installation and untrusted SKILL.md ingestion make this a significant supply-chain and prompt-injection risk.

Confidence: 89%Severity: 78%
Audit Metadata
Analyzed At
May 5, 2026, 09:07 AM
Package URL
pkg:socket/skills-sh/stevengonsalvez%2Fagents-in-a-box%2Fplugins%2F@974cd040bec4827bfa1f5fbae832d8d6f4ec5a75