skill-install

Warn

Audited by Socket on Apr 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is mostly aligned with its stated purpose and does not harvest credentials or exfiltrate data, but it performs transitive skill installation from an external GitHub repo and updates from an unpinned mutable branch. This is a moderate supply-chain risk rather than malware.

Confidence: 92%Severity: 56%
Audit Metadata
Analyzed At
Apr 12, 2026, 05:52 PM
Package URL
pkg:socket/skills-sh/fellowship-dev%2Fdogfooded-skills%2Fskill-install%2F@b9f6a723753d1bea5f880ea654c1e1166e041650