find-skills

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose is coherent, and the `skills` CLI appears to be the official same-project tool, so this is not malware by itself. However, the skill’s core function is to discover and install third-party skills via unpinned `npx` commands, creating meaningful transitive supply-chain risk that is disproportionate to a simple recommendation workflow.

Confidence: 89%Severity: 72%
Audit Metadata
Analyzed At
Apr 1, 2026, 11:56 AM
Package URL
pkg:socket/skills-sh/caomeiyouren%2Fcmyr-skills-agents%2Ffind-skills%2F@370f9fa4763f22e78493cd87b94856fb6c17665e