skill-installer

Fail

Audited by Socket on May 17, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS due to transitive skill installation and support for arbitrary GitHub repos, not because of clear malware behavior. Curated OpenAI-hosted installs are coherent and same-org, but the skill’s footprint expands trust to unreviewed third-party skills fetched from mutable refs and written into the agent’s skills directory.

Confidence: 88%Severity: 72%
Audit Metadata
Analyzed At
May 17, 2026, 03:04 PM
Package URL
pkg:socket/skills-sh/firecrawl%2Fopenai-skills%2Fskill-installer%2F@cdedaa07a81fcfebe1a6d3630f66fd08dc247cbd
Security Audit — socket — skill-installer