skill-installer
Audited by Socket on Sep 15, 2026
2 alerts found:
SecurityAnomalySUSPICIOUS: the skill's purpose matches installing skills, but it materially expands trust by importing arbitrary GitHub-hosted skills into the agent's trusted skill directory with no verification, mutable refs, and a known symlink-related upstream issue. Data flows stay on GitHub and there is no clear credential theft, so this is high-risk transitive/supply-chain behavior rather than confirmed malware.
This module appears to be a functional GitHub-based installer that fetches and installs arbitrary repository content chosen by user input. It does not show overt malware behavior (no exfiltration, credential theft, or hidden execution) within the provided code. The security risk is mainly supply-chain and operational: it executes git based on user-controlled ref/paths, downloads and extracts third-party ZIP archives, and then copies untrusted directories into the local filesystem after only minimal validation (SKILL.md presence). ZIP extraction includes a basic boundary check against path traversal, but additional archive safety (symlink/hardlink/resource exhaustion) and stronger integrity verification (commit pinning/signatures/hashes) are not evident in this module.