cli-skill-collector
Warn
Audited by Socket on Jul 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the local API usage and npm install path are broadly consistent with OmniRoute’s stated purpose, but the skill’s main function is high-risk transitive installation of untrusted third-party agent skills from GitHub into multiple coding tools. The largest concern is not direct malware behavior in this skill, but that it normalizes importing external SKILL.md content into powerful agent environments with management-scoped access and little isolation.
Confidence: 89%Severity: 74%
Audit Metadata