publish-skill

Warn

Audited by Socket on May 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s behavior mostly matches its stated purpose, but it has a meaningful risk footprint because it republishes instruction files, installs skills transitively via the skills CLI, and can push/cherry-pick changes across repos. Install provenance appears consistent with official skills tooling, so this is not malware, but the combination of transitive skill installation and autonomous repo actions makes it medium risk.

Confidence: 86%Severity: 63%
Audit Metadata
Analyzed At
May 17, 2026, 06:43 PM
Package URL
pkg:socket/skills-sh/camacho%2Fai-skills%2Fpublish-skill%2F@5777748bdd026e7a8a9cb4372d338f5c9396b471
Security Audit — socket — publish-skill