skills-cli
Warn
Audited by Socket on May 23, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s behavior matches its stated purpose, but that purpose is itself high-trust: it installs and manages other executable skills. The main concerns are transitive skill installation and unpinned `bunx` execution, plus installs from a personal GitHub source. This is not confirmed malware, but it poses meaningful supply-chain and delegated-trust risk.
Confidence: 90%Severity: 81%
Audit Metadata