skill-system-installer
Warn
Audited by Socket on Apr 11, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s capabilities mostly match its installer purpose, and curated OpenAI/GitHub data flows are coherent, but it materially expands trust by installing arbitrary third-party skills from GitHub, including private repos, via mutable refs and without strong provenance verification. This is a high transitive supply-chain risk rather than confirmed malware.
Confidence: 82%Severity: 72%
Audit Metadata