agent-collabo-updater

Warn

Audited by Socket on Apr 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's behavior largely matches its stated purpose, and the network/data flows stay within the publisher's GitHub repo plus the official Skills CLI path. However, its purpose is to install/update/remove other skills based on a mutable remote manifest, which creates a real transitive supply-chain risk even without evidence of credential theft or unrelated access.

Confidence: 89%Severity: 58%
Audit Metadata
Analyzed At
Apr 11, 2026, 02:58 PM
Package URL
pkg:socket/skills-sh/dev-goraebap%2Fagent-collabo%2Fagent-collabo-updater%2F@6ea97fd8b2b87ccb178e52e21df84bf93710ea1b
Security Audit — socket — agent-collabo-updater