zynkr-skills

Warn

Audited by Socket on Sep 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The stated purpose as a router/orchestrator matches its GitHub lookups, local SKILL.md reads, marketplace checks, and sub-skill routing. The main risk is transitive trust: it tells the agent/user to install a third-party skill repo via `npx skills add` and then serves as a hub that can invoke other skills and make GitHub state changes. Data flows appear first-party to GitHub and zynkr.ai, with no obvious credential exfiltration or off-purpose endpoints, so this is not confirmed malware; the risk comes from broad orchestration and inherited trust rather than deceptive behavior in this file.

Confidence: 90%Severity: 64%
Audit Metadata
Analyzed At
Sep 10, 2026, 07:33 PM
Package URL
pkg:socket/skills-sh/peter-tu-zynkr%2Fzynkr-skill-builder%2Fzynkr-skills%2F@26d0aeec37e707c10a4e99a8e13766f113a23127c716003f063b4dc729899d49
Security Audit — socket — zynkr-skills