install-skills
Warn
Audited by Socket on Sep 6, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally coherent and uses official npm-distributed tooling, but its purpose is to install other skills, creating an inherent transitive-trust and supply-chain risk. No direct credential theft, stealth, or malicious exfiltration is present in this skill itself; the main danger is that it can fetch and install unreviewed third-party skills from broad remote sources using an unpinned CLI.
Confidence: 90%Severity: 72%
Audit Metadata