skills-management
Audited by Socket on Sep 22, 2026
5 alerts found:
Anomalyx3Securityx2SUSPICIOUS. The skill is purpose-aligned as a skill manager, and its documented use of the official Skills CLI is internally consistent. The main risk is inherent transitive trust: it helps the agent discover and install third-party skills from arbitrary repositories, so users are extending trust beyond this skill into whatever gets installed. No direct credential theft, exfiltration, obfuscation, or pre-execution malware pattern is present in the supplied content.
The fragment appears to be a legitimate skill-deletion utility, not malware. However, the unsanitized name argument creates a potentially serious path traversal/arbitrary-directory deletion risk, especially with --force, if an attacker can influence the command-line input or if the tool is invoked on untrusted names. Validate that the resolved target remains within the intended skills directory and reject absolute paths and traversal components. Assessment of the imported agents module requires additional code.
The code is a legitimate skill-directory migration utility and contains no evident malware, exfiltration, persistence, or command execution. However, the unvalidated skill name can potentially escape the configured directories. In particular, --force can cause recursive deletion of an unintended target, and the source is also deleted after copying. Validate the name as a single safe directory component and enforce resolved-path containment beneath both configured base directories before any filesystem mutation.
The code is a legitimate skill-copying utility with a moderate path-handling risk. The unvalidated name argument can potentially escape the configured skill directories, and --force may recursively delete an unintended target. It should restrict name to a single safe directory component, reject absolute paths and traversal segments, and preferably verify resolved paths remain beneath the intended source and destination roots. No direct malware indicators are present in this fragment.
No evidence of malware, data theft, network exfiltration, backdoors, or obfuscation is present. The main security concern is an unvalidated skill name that can enable path traversal or absolute-path manipulation, with --force potentially causing recursive deletion outside the intended skills directories. The utility should restrict names to safe single-directory names and verify resolved paths remain under the appropriate roots. The shown fragment also has an apparent missing closing parenthesis.