find-skills

Warn

Audited by Socket on Apr 6, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's stated purpose matches its behavior, but that purpose is inherently high-trust because it brokers discovery and installation of third-party skills. The upstream CLI appears legitimate and same-org, which lowers malware concern, but the transitive installation model, arbitrary git-source support, and unpinned `npx` execution make this a medium-to-high security risk skill rather than a benign documentation helper.

Confidence: 88%Severity: 62%
Audit Metadata
Analyzed At
Apr 6, 2026, 09:44 PM
Package URL
pkg:socket/skills-sh/Peiiii%2Fnextclaw%2Ffind-skills%2F@28e56fd8fa64d85422df7c1232efbe25e960bb41
Security Audit — socket — find-skills