sync

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the behavior matches the stated purpose, but that purpose is inherently high-trust and broad. It uses official documented tooling, so this is not confirmed malware, yet it installs arbitrary remote skills from an unpinned git URL and does so in bulk with `--all -y`, creating significant supply-chain and transitive-trust risk.

Confidence: 90%Severity: 76%
Audit Metadata
Analyzed At
Mar 31, 2026, 08:39 AM
Package URL
pkg:socket/skills-sh/sjunepark%2Fcustom-skills%2Fsync%2F@241e96d47ed0acfd9a1224fd58a833b22805413f