Grafana Dashboard Scaffolder

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the functional scope fits Grafana dashboard scaffolding, and the stated API usage is broadly coherent, but the distribution path is not aligned with the declared Grafana source. The main risk is transitive third-party skill installation via `npx skills add agentskillexchange/skills`, which introduces supply-chain trust issues and unclear publisher provenance rather than clear malware or exfiltration behavior.

Confidence: 82%Severity: 72%
Audit Metadata
Analyzed At
Mar 29, 2026, 02:36 AM
Package URL
pkg:socket/skills-sh/agentskillexchange%2Fskills%2Fgrafana-dashboard-scaffolder%2F@0381c4b978b0ab09baa54e43be6abd984c5d18f6