fuse-skills
Warn
Audited by Socket on Apr 26, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS due to transitive skill installation and medium supply-chain risk, not because the stated purpose is deceptive. The skill is largely aligned with its fusion goal, but it instructs the agent to fetch/install third-party skills from arbitrary repos via the official CLI, creating a trust-chain risk and possible telemetry exposure. No clear credential theft or overtly malicious behavior is present.
Confidence: 89%Severity: 74%
Audit Metadata