configure-skilllord
Warn
Audited by Socket on Apr 11, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s stated purpose matches its behavior as an installer, but it creates a significant transitive trust chain by cloning an only partially verified personal GitHub repo and installing many downstream skills into active Claude directories. No direct credential theft or exfiltration is evident, so this looks more like a high-risk installer pattern than confirmed malware.
Confidence: 87%Severity: 72%
Audit Metadata