starlight-skills-deployment
Warn
Audited by Socket on Apr 5, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is mostly coherent as deployment/install documentation, but it explicitly enables transitive installation of external skills through an unpinned `npx` CLI workflow. There is no direct credential theft or exfiltration behavior, so this is not malicious, but the trust expansion to third-party skills makes it medium risk.
Confidence: 89%Severity: 58%
Audit Metadata