jeo-skill

Warn

Audited by Socket on Oct 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is coherent with its stated purpose as a catalog/install helper, but that purpose itself creates meaningful transitive-trust risk. Provenance is partly reassuring for the `skills` CLI, yet the skill primarily brokers installation of other skills from external sources, so overall risk is high despite no direct credential theft or exfiltration signals.

Confidence: 91%Severity: 74%
Audit Metadata
Analyzed At
Oct 1, 2026, 11:14 AM
Package URL
pkg:socket/skills-sh/akillness%2Fjeo-skills%2Fjeo-skill%2F@2e5589c671f1594baffd96fb15f40d3b7e25fce835b8161c331c9d1849d00b32
Security Audit — socket — jeo-skill