agent-skills-discovery
Warn
Audited by Socket on Sep 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is purpose-aligned and mostly uses official GitHub/npm channels, so it is not outright malicious, but its core function is to discover and install additional skills, which materially expands agent trust. The transitive-skill-install pattern plus an included `curl|bash` RunPod CLI path make this a high-risk workflow skill even though the documented managers themselves appear legitimate.
Confidence: 91%Severity: 74%
Audit Metadata