agenticskills
Warn
Audited by Socket on Jul 28, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally consistent as an installer, but its footprint is inherently high-trust because it executes a remote mutable shell script and installs a large downstream skill bundle plus an external CLI. Data flows appear proportionate and same-org, so this is not confirmed malicious, but the transitive skill installation and curl|bash pattern make it medium-high risk.
Confidence: 90%Severity: 74%
Audit Metadata