find-skills

Warn

Audited by Socket on Mar 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill's stated purpose (discovering and installing agent skills) aligns with its workflow of querying a registry and enabling installations. However, the footprint introduces notable security concerns: it facilitates transitive, unverifiable installations from an external registry, relies on npx to fetch code without verifiable integrity guarantees, and includes brittle post-install cleanup that could disrupt environments. These factors collectively render the skill Suspicious with medium-high risk. If used in production, tighter controls (verified registries, checksum verification, explicit user consent for each installation, and a safer cleanup process) would be advisable.

Confidence: 65%Severity: 65%
Audit Metadata
Analyzed At
Mar 12, 2026, 07:57 AM
Package URL
pkg:socket/skills-sh/JHostalek%2Fdotclaude%2Ffind-skills%2F@9e42bf0822534db9d910047730ce4717747f14e0
Security Audit — socket — find-skills