fuse-skills

Warn

Audited by Socket on Apr 26, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS due to transitive skill installation and medium supply-chain risk, not because the stated purpose is deceptive. The skill is largely aligned with its fusion goal, but it instructs the agent to fetch/install third-party skills from arbitrary repos via the official CLI, creating a trust-chain risk and possible telemetry exposure. No clear credential theft or overtly malicious behavior is present.

Confidence: 89%Severity: 74%
Audit Metadata
Analyzed At
Apr 26, 2026, 08:10 AM
Package URL
pkg:socket/skills-sh/n-n-code%2Fn-n-code-skills%2Ffuse-skills%2F@5186491fd332906bf71cbd64a78e8dca42290b27