learn
Warn
Audited by Socket on Mar 30, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the core purpose is coherent, but the skill’s deployment path and authority expansion are not fully proportionate. The main risk is unpinned execution of an unverifiably documented `skiller` CLI plus transitive skill installation behavior; web research with write access adds secondary prompt-injection risk.
Confidence: 86%Severity: 74%
Audit Metadata