antigravity-lazy-packs
Warn
Audited by Socket on May 31, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally coherent as an installer, but its real function is to transitively install and execute other third-party skills from a personal GitHub repo. The official `npx skills` path lowers concern somewhat, yet the manual fallback and inherited trust chain make this a medium-high supply-chain risk rather than a benign workflow helper.
Confidence: 87%Severity: 76%
Audit Metadata