project-skill-installer

Warn

Audited by Socket on May 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s stated purpose mostly matches its behavior, and it does require user confirmation before installs. However, its main function is transitive installation of additional skills via remote `npx` commands, which meaningfully increases supply-chain and trust-chain risk even when using the documented skills.sh workflow. No clear credential theft or exfiltration is present, but the installation footprint is higher risk than a simple recommendation skill.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
May 10, 2026, 03:03 PM
Package URL
pkg:socket/skills-sh/learnwy%2Fskills%2Fproject-skill-installer%2F@e0abb492ac1f04eb60b5d7a2476a3b56ff3b37a3