find-skills

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s stated purpose matches its behavior, and the `skills` CLI appears official to the ecosystem, so this is not confirmed malware. However, it is inherently high-trust: it instructs the agent to discover and install additional third-party skills from broad sources, including non-vetted repos, with global and non-interactive flags. The main risk is transitive skill installation and supply-chain expansion, not direct credential theft or exfiltration in this skill itself.

Confidence: 90%Severity: 74%
Audit Metadata
Analyzed At
Mar 21, 2026, 04:46 PM
Package URL
pkg:socket/skills-sh/stvlynn%2Fqclaw-skills%2Ffind-skills%2F@8d143df66988eb1ef4fef9315ff6c278b40c583c