zynkr-skills
Warn
Audited by Socket on Sep 10, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The stated purpose as a router/orchestrator matches its GitHub lookups, local SKILL.md reads, marketplace checks, and sub-skill routing. The main risk is transitive trust: it tells the agent/user to install a third-party skill repo via `npx skills add` and then serves as a hub that can invoke other skills and make GitHub state changes. Data flows appear first-party to GitHub and zynkr.ai, with no obvious credential exfiltration or off-purpose endpoints, so this is not confirmed malware; the risk comes from broad orchestration and inherited trust rather than deceptive behavior in this file.
Confidence: 90%Severity: 64%
Audit Metadata