install-xzy-skills
Warn
Audited by Socket on May 14, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the official CLI provenance lowers installer-malware concern, but the skill's real footprint is to bulk-install an unreviewed third-party skill collection via a transitive trust chain. The wildcard `--all` behavior and auto-confirm make the scope disproportionate to a simple installer helper.
Confidence: 90%Severity: 74%
Audit Metadata