skill-marketplace

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS. The skill's stated purpose is marketplace discovery, but its actual footprint is to autonomously import and execute third-party skills from an unofficial aggregator, creating a high-risk transitive trust chain. The main issue is not direct malware in this file, but unsafe supply-chain expansion, prompt-injection exposure, and execution of unvetted remote instructions.

Confidence: 93%Severity: 88%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:16 PM
Package URL
pkg:socket/skills-sh/cityfish91159%2Fmaihouses%2Fskill-marketplace%2F@3f67711a1fb7f8b0eaf927df65eeae77bef47346