skill-scanner
Warn
Audited by Socket on May 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated purpose mostly matches the read/scan behavior, but the skill hardcodes an API token and transmits full local skill contents to a remote model endpoint whose exact public documentation could not be verified. The main risks are credential handling, external code/data exposure, and recursive analysis of untrusted skill content rather than confirmed malware.
Confidence: 87%Severity: 81%
Audit Metadata