find-agents

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose matches its behavior, but its footprint carries elevated risk because it executes `agentshq` via `npx` and installs arbitrary third-party agents from repos/URLs, creating a transitive trust chain. The explicit-user-only rules and clear mutation guardrails make it more coherent than malicious, but the install/update path is still high-risk for supply-chain reasons.

Confidence: 86%Severity: 78%
Audit Metadata
Analyzed At
Apr 1, 2026, 06:54 PM
Package URL
pkg:socket/skills-sh/ulpi-io%2Fskills%2Ffind-agents%2F@b1b97fef75f9c80bd486421016a589c3303a1f13