install-xzy-skills

Warn

Audited by Socket on May 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the official CLI provenance lowers installer-malware concern, but the skill's real footprint is to bulk-install an unreviewed third-party skill collection via a transitive trust chain. The wildcard `--all` behavior and auto-confirm make the scope disproportionate to a simple installer helper.

Confidence: 90%Severity: 74%
Audit Metadata
Analyzed At
May 14, 2026, 02:56 PM
Package URL
pkg:socket/skills-sh/sanxzy%2FSkills%2Finstall-xzy-skills%2F@f5ff14aea545c17125ed1652bd1110be075d7a8f
Security Audit — socket — install-xzy-skills