agenticskills

Warn

Audited by Socket on Jul 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent as an installer, but its footprint is inherently high-trust because it executes a remote mutable shell script and installs a large downstream skill bundle plus an external CLI. Data flows appear proportionate and same-org, so this is not confirmed malicious, but the transitive skill installation and curl|bash pattern make it medium-high risk.

Confidence: 90%Severity: 74%
Audit Metadata
Analyzed At
Jul 28, 2026, 01:52 PM
Package URL
pkg:socket/skills-sh/akillness%2Fjeo-skills%2Fagenticskills%2F@7e251c8d20d20557586dff353f180c5991e23c39c04e7a1cd6ac33c34276c819
Security Audit — socket — agenticskills