skill-adapter

Warn

Audited by Socket on May 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's core idea is coherent, but its footprint is broader than needed. The main risk is not external supply chain or credential theft; it is combining unrestricted shell access with adaptation from arbitrary local plugin/script content, which creates a meaningful indirect prompt-injection and overbroad-execution risk.

Confidence: 89%Severity: 64%
Audit Metadata
Analyzed At
May 26, 2026, 10:55 PM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus-skills%2Fskill-adapter%2F@ea41b201a2bbf4b00cac942637b04beda02c0241
Security Audit — socket — skill-adapter