opensource-project-learning

Warn

Audited by Socket on May 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core teaching and local note-taking behavior fits the stated purpose, but the skill also encourages executing arbitrary third-party project install/run commands and references another skill, expanding trust beyond a simple learning guide. The claude-hud example contains a publisher mismatch (Anthropic vs jarrodwatts), which weakens install trust. No clear credential harvesting or outbound exfiltration is present, so this is better classified as suspicious/high-vulnerability rather than malicious.

Confidence: 85%Severity: 61%
Audit Metadata
Analyzed At
May 10, 2026, 04:24 AM
Package URL
pkg:socket/skills-sh/kongshan001%2Fopensource-project-learning-skill%2Fopensource-project-learning%2F@c6404ae3c91342ac882a9a92c50010dcfad1aac1