sync-skill-to-jay

Warn

Audited by Socket on Apr 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill's purpose broadly matches repo sync/publish automation, but its footprint includes pushing local content to GitHub, deleting the local skill, and installing a remote skill via `npx skills add`. The main concern is transitive skill installation and moderate supply-chain risk from treating a personal GitHub repo as the reinstall source for agent-executed instructions.

Confidence: 91%Severity: 76%
Audit Metadata
Analyzed At
Apr 4, 2026, 04:31 AM
Package URL
pkg:socket/skills-sh/nangongwentian-fe%2Fjay-skills%2Fsync-skill-to-jay%2F@341e33b9ca37b45a2b3d087b64ee003d4814192b