skill-installer

Warn

Audited by Socket on Apr 6, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is coherent with its stated purpose, but that purpose is to install other skills, creating significant transitive-trust risk. Public evidence shows dependency on unverified external CLIs and unspecified marketplace trust boundaries, while no credential harvesting or explicit exfiltration is shown.

Confidence: 88%Severity: 68%
AnomalyLOW
index.ts

This fragment does not show explicit malicious code (no eval/exec, obfuscation, or exfiltration), but it exposes a high-impact capability: a remote client can request installation of a marketplace “skill” via saveInstalledSkill(), making supply-chain and downstream code-loading behavior the key risk. Risk should be reviewed by inspecting getMarketplaceSkills() authenticity/verification, authorization around tool calls, and the exact side effects and safety constraints implemented inside saveInstalledSkill() (not visible here).

Confidence: 52%Severity: 60%
Audit Metadata
Analyzed At
Apr 6, 2026, 10:44 AM
Package URL
pkg:socket/skills-sh/teachingai%2Ffull-stack-skills%2Fskill-installer%2F@6a1b43140c1ecee203b7676c42ddbe4f2f45faed