sync-skill-to-jay
Warn
Audited by Socket on Apr 4, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill's purpose broadly matches repo sync/publish automation, but its footprint includes pushing local content to GitHub, deleting the local skill, and installing a remote skill via `npx skills add`. The main concern is transitive skill installation and moderate supply-chain risk from treating a personal GitHub repo as the reinstall source for agent-executed instructions.
Confidence: 91%Severity: 76%
Audit Metadata