skill-group

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose matches its behavior as a meta-orchestrator, but its footprint is risky because it instructs transitive installation and full execution of third-party sub-skills, defaulting to a personal GitHub registry unrelated to the CLI publisher. No confirmed malware or direct credential theft is present in this skill alone, but it meaningfully expands trust and prompt-injection surface.

Confidence: 90%Severity: 76%
Audit Metadata
Analyzed At
Apr 2, 2026, 05:59 AM
Package URL
pkg:socket/skills-sh/wghust%2Fstark-skills%2Fskill-group%2F@cb7852c2bbdc8275fc22c0848ea5a4f3325aca0d