skill-discovery

Warn

Audited by Socket on Mar 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated discovery purpose is plausible, but the default auto-import of remote community skills and instruction to read/follow imported SKILL.md files creates a transitive trust and prompt-injection supply-chain risk disproportionate to simple discovery. Lack of verifiable provenance, signing, or endpoint transparency keeps risk elevated even without explicit malware behavior.

Confidence: 87%Severity: 78%
Audit Metadata
Analyzed At
Mar 30, 2026, 06:43 AM
Package URL
pkg:socket/skills-sh/HKUDS%2FOpenSpace%2Fskill-discovery%2F@ab6c320a8bfd73f2160bbe3aff967a025aa3cb59
Security Audit — socket — skill-discovery