search-skill
Warn
Audited by Socket on Aug 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill's stated purpose matches its behavior, but that behavior is inherently high-risk: it searches untrusted external ecosystems and can autonomously install another skill, which then inherits agent privileges. The first-party add-skill path and trust gates help, and there is no clear credential exfiltration, but the transitive installation chain plus external-content processing and autonomous repo changes make this a high security-risk skill.
Confidence: 87%Severity: 79%
Audit Metadata