use-skills-from-neuron
Warn
Audited by Socket on Sep 13, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The main issue is not classic malware behavior but that this skill is a remote skill loader: it retrieves instructions from Nucleus and tells the agent to execute them as if they were local. Same-org Nucleus MCP documentation makes the direct integration look legitimate, but the transitive trust and prompt-injection surface are significant, and the fallback migrator script is underspecified.
Confidence: 90%Severity: 76%
Audit Metadata