Installing Skills System

Warn

Audited by Socket on May 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s behavior matches its stated installer purpose, and the referenced repo/script appear to be same-source and locally scoped after download. However, it uses unpinned curl|bash and, more importantly, installs a whole external skill system with persistent CLAUDE.md changes, creating a significant transitive-trust and persistence risk even without clear evidence of malware or exfiltration.

Confidence: 89%Severity: 74%
Audit Metadata
Analyzed At
May 30, 2026, 03:31 PM
Package URL
pkg:socket/skills-sh/obra%2Fclank%2Finstalling-skills-system%2F@ab893f22f1aa45e12464b4899eadcd320bd82961
Security Audit — socket — Installing Skills System