suggest-awesome-github-copilot-skills
Fail
Audited by Socket on Mar 18, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
SUSPICIOUS: The skill's behavior mostly matches its stated purpose and uses GitHub-owned sources, so it is not fundamentally deceptive. However, it performs transitive skill installation from mutable remote content, including community-contributed SKILL.md instructions and bundled assets, which expands trust beyond local review and creates medium risk even without credential harvesting or obvious exfiltration.
Confidence: 87%Severity: 62%
Audit Metadata