find-skill

Warn

Audited by Socket on May 5, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose matches discovery/install of skills, but the skill's core behavior is to expand the agent's capability set by installing additional skills, which is inherently high-trust. Combined with direct reading of local credential files and lack of integrity guidance for installed skills, this is a meaningful security risk even without clear evidence of malicious intent.

Confidence: 83%Severity: 72%
Audit Metadata
Analyzed At
May 5, 2026, 12:12 PM
Package URL
pkg:socket/skills-sh/gooseworks-ai%2Fgoose-skills%2Ffind-skill%2F@a5b06488697d815a7ab6754760a85af254d063c1