multica-skill-importing

Warn

Audited by Socket on Aug 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is internally coherent, but its core function is transitive skill installation from external sources, including arbitrary GitHub URLs. That makes it meaningfully risky even without direct credential theft or obvious malicious behavior.

Confidence: 90%Severity: 68%
Audit Metadata
Analyzed At
Aug 26, 2026, 02:50 PM
Package URL
pkg:socket/skills-sh/multica-ai%2Fmultica%2Fmultica-skill-importing%2F@498a71cb09e31911f58bf18d921eea472cdf0c68a30457c62bcad73f72d691b8
Security Audit — socket — multica-skill-importing