learn

Warn

Audited by Socket on Mar 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core purpose is coherent, but the skill’s deployment path and authority expansion are not fully proportionate. The main risk is unpinned execution of an unverifiably documented `skiller` CLI plus transitive skill installation behavior; web research with write access adds secondary prompt-injection risk.

Confidence: 86%Severity: 74%
Audit Metadata
Analyzed At
Mar 30, 2026, 01:22 AM
Package URL
pkg:socket/skills-sh/udecode%2Fbetter-convex%2Flearn%2F@9d72e1009846418b7da33bf5289c00020ebc046f