octocode-search-skill
Warn
Audited by Socket on May 8, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
The skill is coherent with its stated purpose, but that purpose is inherently high-risk because it installs arbitrary third-party agent skills from GitHub. Main concern is transitive trust and indirect prompt injection from untrusted SKILL.md content, not overt malware or credential theft.
Confidence: 89%Severity: 62%
Audit Metadata