navigate-skills
Warn
Audited by Socket on Aug 1, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The routing purpose mostly matches the local catalog reads, but the skill adds optional outbound telemetry to a config-defined endpoint and, more importantly, instructs transitive installation of third-party skills via unpinned `npx skills add` from GitHub URLs. The biggest risk is supply-chain and inherited trust from externally installed skills, not confirmed malware.
Confidence: 88%Severity: 74%
Audit Metadata