new-skill

Warn

Audited by Socket on May 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s main purpose is benign documentation, but it normalizes transitive skill installation and remote doc fetching. Install sources are mostly official and coherent, so this is not malicious; the primary concern is medium security risk from unpinned `npx` usage and loading arbitrary third-party skills.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
May 12, 2026, 08:32 AM
Package URL
pkg:socket/skills-sh/remorses%2Fkimaki%2Fnew-skill%2F@4b6f61a9ad325589e676b682167fc13f65d7b77c