skill-installer

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose matches the capabilities, but the skill’s main function is transitive installation of third-party skills from mutable, unauthenticated sources, including an unofficial aggregator. Its review/confirmation steps reduce risk, yet they do not remove the fundamental supply-chain and trust-extension hazards of installing other skills.

Confidence: 92%Severity: 79%
Audit Metadata
Analyzed At
Apr 9, 2026, 11:43 AM
Package URL
pkg:socket/skills-sh/yipng05-max%2F-skills%2Fskill-installer%2F@c73496adcd3eafb67daaca5cedf27d49aa5ae4e6