learn

Warn

Audited by Socket on May 6, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill's behavior is broadly aligned with its stated marketplace purpose and uses same-org official infrastructure, so it is not outright malicious. However, it is a high-trust bootstrapper: it executes a remotely resolved CLI, performs self-updates, installs additional skills from a registry, and auto-submits feedback, creating meaningful supply-chain, transitive-trust, and autonomous-action risk.

Confidence: 87%Severity: 76%
Audit Metadata
Analyzed At
May 6, 2026, 01:56 PM
Package URL
pkg:socket/skills-sh/agentskill-sh%2Fags%2Flearn%2F@c27a35d1bbb84f706a738a65c714e4174468e952