skill-installer
Warn
Audited by Socket on Sep 14, 2026
1 alert found:
SecuritySecurityskill-report.json
MEDIUMSecurityMEDIUM
skill-report.json
The fragment is not itself malicious executable code; it is an audit report and documentation for a skill installer. It documents a significant supply-chain risk because unverified remote GitHub content can be persistently installed, and system skills may be overwritten. No direct malware, credential theft, obfuscation, or data exfiltration is demonstrated in the supplied fragment. Review and constrain the referenced helper scripts, require immutable commits and content verification, enforce destination/path protections, and prohibit system-skill overwrites.
Confidence: 94%Severity: 72%
Audit Metadata