my-skill

Warn

Audited by Socket on Apr 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose is coherent, but the skill is a high-trust router that delegates to unseen workflow files, depends on another skill, and may consume untrusted registry content while having local write/manage powers. External CLIs are plausibly official, so this is not confirmed malware, but the transitive-trust and prompt-injection surface make the skill medium risk.

Confidence: 81%Severity: 56%
Audit Metadata
Analyzed At
Apr 26, 2026, 07:05 PM
Package URL
pkg:socket/skills-sh/PPsteven%2Fskills%2Fmy-skill%2F@59118b954701342de1767bfd47cccfe99e1590c5