find-skills

Fail

Audited by Socket on Mar 1, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The 'find-skills' skill is functionally appropriate for discovering and recommending agent skills, but it promotes high-risk supply-chain and autonomy behaviors: unpinned installs, global unattended installs (-g -y), and delegation to an unverified installer. There is no explicit malicious code in the provided text, but following its recommendations without mitigation creates a significant attack surface for supply-chain compromise and untrusted code execution. Recommended mitigations: require explicit per-install human confirmation, avoid '-g -y' in automated flows, pin install commands to commit SHAs or use checksums, validate publisher identity, sandbox or limit installer privileges, and log/notify users of any install operations.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 1, 2026, 12:36 PM
Package URL
pkg:socket/skills-sh/tyk-lab%2Fmy-ai-skill%2Ffind-skills%2F@5ddd28aa7c8724e17886e216ffe6d92c634f3a33