suggest-awesome-github-copilot-skills

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: The skill's behavior mostly matches its stated purpose and uses GitHub-owned sources, so it is not fundamentally deceptive. However, it performs transitive skill installation from mutable remote content, including community-contributed SKILL.md instructions and bundled assets, which expands trust beyond local review and creates medium risk even without credential harvesting or obvious exfiltration.

Confidence: 87%Severity: 62%
Audit Metadata
Analyzed At
Mar 18, 2026, 04:48 PM
Package URL
pkg:socket/skills-sh/github%2Fawesome-copilot%2Fsuggest-awesome-github-copilot-skills%2F@751f84dfd1e785261c76a0d76a1d8498484b3746