skiplagged

Warn

Audited by Socket on May 1, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
metadata.json

No direct malicious code is visible in this fragment because it only defines metadata and an install command. The primary risk is supply-chain integrity: the installer downloads SKILL.md from a mutable upstream URL (main branch) and writes it locally without any integrity verification, making tampering/content drift a concern. Review and pin the upstream revision and verify integrity (checksum/signature) before trusting or loading the downloaded SKILL.md.

Confidence: 62%Severity: 60%
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s travel-search purpose is plausible, but its footprint is inflated by Canifi-managed curl|bash installers and optional credential capture for a service that reportedly works in guest mode. I see no confirmed malicious exfiltration, yet install trust and credential-forwarding risks are material and not well bounded to the stated purpose.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
May 1, 2026, 11:30 AM
Package URL
pkg:socket/skills-sh/diegosouzapw%2Fawesome-omni-skill%2Fskiplagged%2F@8fce066baab2658e4854a7c723471b347dc64637
Security Audit — socket — skiplagged