anthropic-cybersecurity-skills
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally coherent as a cybersecurity skill library, but it materially expands trust by instructing installation of another skill/repository through the skills CLI and then encourages loading/executing third-party helper scripts. No direct credential theft or covert exfiltration is shown, so this is not confirmed malware, but the transitive-trust and downstream execution footprint make it a high-risk meta-skill.
Confidence: 88%Severity: 76%
Audit Metadata