skill-installer

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Security
SecurityMEDIUM
skill-report.json

The fragment is not itself malicious executable code; it is an audit report and documentation for a skill installer. It documents a significant supply-chain risk because unverified remote GitHub content can be persistently installed, and system skills may be overwritten. No direct malware, credential theft, obfuscation, or data exfiltration is demonstrated in the supplied fragment. Review and constrain the referenced helper scripts, require immutable commits and content verification, enforce destination/path protections, and prohibit system-skill overwrites.

Confidence: 94%Severity: 72%
Audit Metadata
Analyzed At
Sep 14, 2026, 11:53 PM
Package URL
pkg:socket/skills-sh/aiskillstore%2Fmarketplace%2Fskill-installer%2F@00d5d86d292fb6b4c289d7680ec660b86e442f3869b00dd1217bc722f1f08463