import-skills-to-skilder
Warn
Audited by Socket on Jul 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's main behavior is coherent with its stated purpose—centralizing local skills into Skilder—and it uses same-brand Skilder endpoints with OAuth rather than asking for raw secrets. However, it performs broad local file discovery and uploads content verbatim to a remote service, public verification of the MCP tooling is limited from the provided evidence, and it depends on an unreviewed companion skill for connection setup. This looks more like a legitimate but medium-risk data-export/admin skill than malware.
Confidence: 84%Severity: 56%
Audit Metadata