cnife-skills-repo

Warn

Audited by Socket on Jun 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s core purpose is coherent for repository maintenance, and there is no direct credential theft or hidden exfiltration. The main concern is transitive trust: it instructs the agent to install skills from a third-party skills ecosystem/CLI and from the CNife repo without separate verification, which makes the overall workflow moderately risky.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 17, 2026, 08:42 AM
Package URL
pkg:socket/skills-sh/CNife%2Fskills%2Fcnife-skills-repo%2F@325a8db6e7167029198a52c4ef2ee4139c17c90704c96402428c94b5af022e9c
Security Audit — socket — cnife-skills-repo