install-recommended-skills

Warn

Audited by Socket on Jul 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is coherent in purpose, but its sole function is transitive installation of multiple third-party skills from a personal GitHub repo, without version pinning. Data flows stay within official GitHub CLI paths and there is no direct credential exfiltration, but the trust expansion to downstream skills makes the overall risk medium-high.

Confidence: 89%Severity: 72%
Audit Metadata
Analyzed At
Jul 29, 2026, 12:05 PM
Package URL
pkg:socket/skills-sh/atman-33%2Fagent-harness%2Finstall-recommended-skills%2F@832c7cc268ad2c24aad27ce8c812297ba19f9092013455560301d5a1c5646780
Security Audit — socket — install-recommended-skills