@554/skill-installer

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose matches a skill marketplace installer, but the footprint is high risk because it installs other skills from third-party sources, relies on an unverified Fly-hosted gateway, and uses an unpinned npx install path. The publish flow is plausible, yet it forwards local files and auth tokens to an external gateway whose ownership is not publicly verifiable from the provided evidence.

Confidence: 89%Severity: 82%
Audit Metadata
Analyzed At
Mar 18, 2026, 03:12 AM
Package URL
pkg:socket/skills-sh/Starchild-ai-agent%2Fcommunity-skills%2F554skill-installer%2F@394a4e91515f896cae5093a387ddd5c45a29c726
Security Audit — socket — @554/skill-installer