external-skill-acquisition

Warn

Audited by Socket on May 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose matches the capability to find and install skills, but the footprint is still high-risk because it is fundamentally a transitive skill installer. It routes discovery through external services, references partially unverifiable install commands, and explicitly injects newly acquired untrusted skill content into the active session, creating a strong prompt-injection and delegated-trust risk even without direct malware behavior.

Confidence: 90%Severity: 83%
Audit Metadata
Analyzed At
May 19, 2026, 10:59 AM
Package URL
pkg:socket/skills-sh/rooftop-Owl%2Fskill-factory%2Fexternal-skill-acquisition%2F@7b70a2654e750352368be55156e4305029a1c382
Security Audit — socket — external-skill-acquisition