find-skills

Warn

Audited by Socket on May 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose mostly matches its behavior and the core CLI appears official, but it is a transitive installer skill that can globally add arbitrary third-party skills with skipped confirmation. The main risk is delegated trust expansion, not overt malware or credential theft.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
May 14, 2026, 09:52 AM
Package URL
pkg:socket/skills-sh/KimYx0207%2Ffindskill%2Ffind-skills%2F@6fb359e346b27140bd0f1c2fc0e36e9f5d32ab5f