skill-hub-builder

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s core purpose is coherent, but it materially increases risk by automating transitive installation and redistribution of third-party skills from arbitrary repositories. The main concern is not hidden exfiltration; it is the creation of a supply-chain and prompt-injection trust chain that can load unreviewed skills into an agent environment.

Confidence: 87%Severity: 74%
Audit Metadata
Analyzed At
Apr 2, 2026, 11:32 AM
Package URL
pkg:socket/skills-sh/zhangga%2Faihub%2Fskill-hub-builder%2F@ccd057d6eced051dd8b5e34132ebb30144a1f906