skillify

Warn

Audited by Socket on Sep 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core skill purpose is coherent, and the PyYAML dependency is proportionate, but the skill also instructs the agent to install skills from a third-party repo via the skills CLI, creating transitive trust beyond simple local skillification. The reduced-approval filing directive adds moderate autonomy risk. No confirmed credential theft, exfiltration, or malicious payload execution is shown.

Confidence: 88%Severity: 64%
Audit Metadata
Analyzed At
Sep 7, 2026, 03:35 PM
Package URL
pkg:socket/skills-sh/broomva%2Fskills%2Fskillify%2F@8453617c46fb11def352cacea76243a1c8491e39f7dcbd0f2e88f905504b2d36
Security Audit — socket — skillify