alibabacloud-find-skills

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core search/discovery behavior is mostly consistent and uses official Alibaba Cloud tooling, but the skill overreaches by directing installation of additional skills. The main risk is transitive skill installation, plus moderate supply-chain risk from `curl|bash` and npm-based installs. No clear credential theft or malicious exfiltration is present in this skill itself.

Confidence: 89%Severity: 61%
Audit Metadata
Analyzed At
May 2, 2026, 09:06 AM
Package URL
pkg:socket/skills-sh/aliyun%2Falibabacloud-skills%2Falibabacloud-find-skills%2F@0da2669e381180603e81e8b2d9970f58a8c5a593
Security Audit — socket — alibabacloud-find-skills