skill-author

Warn

Audited by Socket on Sep 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s stated authoring behavior is coherent and locally scoped, but it includes a transitive skill-install step from a GitHub URL via an unpinned CLI. No credential harvesting or exfiltration is evident, yet the install trust chain is broader than necessary for a documentation/authoring skill.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Sep 10, 2026, 07:32 PM
Package URL
pkg:socket/skills-sh/peter-tu-zynkr%2Fzynkr-skill-builder%2Fskill-author%2F@fb00bf96bfdbb0401721c9a5f6ba086ccf1bd1f1b0a40c50d2a49315e063b5c5
Security Audit — socket — skill-author