plugins-management
Warn
Audited by Socket on Sep 22, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s capabilities fit its stated plugin-management purpose, and verified references to GitHub CLI, OpenCode docs, and npm are legitimate. The main risk is inherent supply-chain exposure from helping the agent install/publish/manage third-party plugins from npm and arbitrary marketplace URLs, which can introduce highly privileged code, but there is no clear credential theft, hidden execution, or malicious exfiltration in this skill itself.
Confidence: 89%Severity: 56%
Audit Metadata