install-github-plugin

Warn

Audited by Socket on Apr 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s stated purpose is coherent, and it relies on official GitHub/Claude tooling, but its actual function is to bypass normal marketplace packaging and install third-party skills/plugins from arbitrary GitHub repos. The main risk is transitive trust and prompt-injection from unreviewed repo content, not confirmed malware or credential theft.

Confidence: 91%Severity: 74%
Audit Metadata
Analyzed At
Apr 11, 2026, 01:07 AM
Package URL
pkg:socket/skills-sh/tebjan%2Fagent-skills%2Finstall-github-plugin%2F@88047d2cf6ac43f08ec01ddb048250c1fab22ea3