develop
Warn
Audited by Socket on Aug 28, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s workflow purpose is coherent, but it materially expands trust by instructing the agent to install and rely on multiple remote child skills, including third-party GitHub sources, with mutable version selection. No direct credential theft or exfiltration is evident, but transitive skill installation plus autonomous repo actions makes this medium-to-high risk.
Confidence: 89%Severity: 74%
Audit Metadata