agent-skill-stack
Warn
Audited by Socket on Jul 23, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated purpose is coherent, but the skill’s footprint is inherently high-trust because it discovers, evaluates, and installs other skills from third-party sources. Main risk is transitive supply-chain exposure and prompt-injection from untrusted skill content, not confirmed malware.
Confidence: 89%Severity: 74%
Audit Metadata