install-skill
Warn
Audited by Socket on Aug 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s purpose is coherent, and its GitHub data flow is mostly consistent with that purpose, but its footprint is high-risk: it fetches arbitrary third-party skill packs, processes untrusted instruction files, writes them into the repo, and can auto-merge the result. The official GitHub CLI and GitHub endpoints reduce provenance concerns for transport, yet the transitive trust in arbitrary community packs plus autonomous merge behavior makes this a high security-risk skill rather than benign.
Confidence: 88%Severity: 76%
Audit Metadata