find-skills-cn
Audited by Socket on Mar 7, 2026
1 alert found:
Obfuscated FileThe skill's stated purpose (discovering and installing AI agent skills) is broadly aligned with the described capabilities (search, present options, install via Skills CLI). However, the reliance on transitive installations from external sources (GitHub, skills.sh) introduces notable supply-chain risk and necessitates careful vetting of installed skills. Data flows involve transmitting user queries to external registries and potentially executing third-party code, which raises security and trust concerns. Overall, the footprint is coherent with its purpose but warrants elevated scrutiny (suspicious-to-high risk) due to transitive installs and potential credential/data exposure during the install process.