related-skill
Warn
Audited by Socket on Sep 14, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's stated purpose matches its behavior, but that behavior is itself high-risk because it primarily instructs the agent to install more skills. The main issue is transitive trust expansion through `npx skills add ...`; install provenance is partly consistent with the inference.sh ecosystem, so this is not confirmed malware, but it meaningfully increases attack surface and should be treated as high-risk workflow expansion.
Confidence: 90%Severity: 78%
Audit Metadata