external-skill-acquisition
Warn
Audited by Socket on May 19, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated purpose matches the capability to find and install skills, but the footprint is still high-risk because it is fundamentally a transitive skill installer. It routes discovery through external services, references partially unverifiable install commands, and explicitly injects newly acquired untrusted skill content into the active session, creating a strong prompt-injection and delegated-trust risk even without direct malware behavior.
Confidence: 90%Severity: 83%
Audit Metadata