skill-hub-builder
Warn
Audited by Socket on Apr 2, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s core purpose is coherent, but it materially increases risk by automating transitive installation and redistribution of third-party skills from arbitrary repositories. The main concern is not hidden exfiltration; it is the creation of a supply-chain and prompt-injection trust chain that can load unreviewed skills into an agent environment.
Confidence: 87%Severity: 74%
Audit Metadata