agent-skills-discovery

Warn

Audited by Socket on Sep 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is purpose-aligned and mostly uses official GitHub/npm channels, so it is not outright malicious, but its core function is to discover and install additional skills, which materially expands agent trust. The transitive-skill-install pattern plus an included `curl|bash` RunPod CLI path make this a high-risk workflow skill even though the documented managers themselves appear legitimate.

Confidence: 91%Severity: 74%
Audit Metadata
Analyzed At
Sep 18, 2026, 08:11 AM
Package URL
pkg:socket/skills-sh/rajivmehtaflex%2Fpower-utility%2Fagent-skills-discovery%2F@524b4019870c1fd2e4664f65a15592312f06bab25635e5f3a504334cd2698c10
Security Audit — socket — agent-skills-discovery