use-skills-from-neuron

Warn

Audited by Socket on Sep 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The main issue is not classic malware behavior but that this skill is a remote skill loader: it retrieves instructions from Nucleus and tells the agent to execute them as if they were local. Same-org Nucleus MCP documentation makes the direct integration look legitimate, but the transitive trust and prompt-injection surface are significant, and the fallback migrator script is underspecified.

Confidence: 90%Severity: 76%
Audit Metadata
Analyzed At
Sep 13, 2026, 03:58 PM
Package URL
pkg:socket/skills-sh/celeroncoder%2Fskills%2Fuse-skills-from-neuron%2F@0ee5a2904286b5753ef8cd8844ad4c5bc690940db628aa74e69e493f81c0f83f
Security Audit — socket — use-skills-from-neuron