skill-finder

Warn

Audited by Socket on May 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose is coherent, but this skill materially increases risk by instructing the agent to discover, fetch, and temporarily install third-party skills from outside the curated catalog. Its safeguards (catalog pre-check, sandbox eval, mandatory pinning) reduce but do not remove the transitive-install, supply-chain, and prompt-injection risks inherent to evaluating untrusted skills.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
May 12, 2026, 03:54 AM
Package URL
pkg:socket/skills-sh/mizchi%2Fskills%2Fskill-finder%2F@e1b4722bb2fcffa1502d07654832ed996d94c4cd