audit-skill
Warn
Audited by Socket on Jun 15, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The workflow is coherent for auditing and repairing installed skills, and it uses an apparently official `skills` CLI. The main risk is transitive trust: this skill installs other skills from a personal repo/local source into multiple global agent environments, expanding impact if that source is compromised. Medium supply-chain risk, low evidence of direct malware or credential theft.
Confidence: 100%Severity: 60%
Audit Metadata