sjskills
Warn
Audited by Socket on Sep 8, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s purpose and capabilities are internally coherent for skill-state reconciliation, and there is no clear credential harvesting or third-party proxying. However, it depends on an unverified local `sjskills` executable and authorizes broad project/global mutations through that opaque CLI, which triggers high supply-chain risk even though malicious intent is not confirmed.
Confidence: 84%Severity: 82%
Audit Metadata