skill-author
Warn
Audited by Socket on Sep 10, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s stated authoring behavior is coherent and locally scoped, but it includes a transitive skill-install step from a GitHub URL via an unpinned CLI. No credential harvesting or exfiltration is evident, yet the install trust chain is broader than necessary for a documentation/authoring skill.
Confidence: 87%Severity: 56%
Audit Metadata