share-skill

Warn

Audited by Socket on Jun 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s main behavior broadly matches its stated purpose, but it requests expansive agent permissions, edits Claude Code settings, can exfiltrate content via arbitrary git remotes, and chains into other skills. This is not clearly malicious, but the permission scope and trust model are wider than necessary for a simple skill-sharing utility.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 16, 2026, 07:19 AM
Package URL
pkg:socket/skills-sh/aiskillstore%2Fmarketplace%2Fshare-skill%2F@a0d1eba06b194ba992a3534c026272887623c7e8a754e8073c7b89c310aaad47
Security Audit — socket — share-skill