find-skills

Fail

Audited by Socket on Mar 15, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: the skill is internally consistent and uses an apparently official CLI, but its main purpose is to discover and install other skills, including third-party sources. That transitive installation behavior is a meaningful security risk even without direct malicious behavior or credential theft in this skill itself.

Confidence: 88%Severity: 74%
Audit Metadata
Analyzed At
Mar 15, 2026, 06:59 AM
Package URL
pkg:socket/skills-sh/vercel-labs%2Fadd-skill%2Ffind-skills%2F@3013fdeb8a11b10b1eb795ec3ae8bfca38f7c26d