setup-skilly

Warn

Audited by Socket on Aug 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose is coherent, but its trust model is weak: it executes a GitHub-hosted CLI via npx, bootstraps ongoing transitive skill installation/sync, and enables automatic PR-generating workflows. The main concern is supply-chain and inherited trust breadth rather than confirmed malicious behavior.

Confidence: 83%Severity: 76%
Audit Metadata
Analyzed At
Aug 31, 2026, 11:08 PM
Package URL
pkg:socket/skills-sh/timschoch%2Fskilly%2Fsetup-skilly%2F@69d455e913189267dca6eaebd17ea5660818b9428c8429631dc58d8d061ce209
Security Audit — socket — setup-skilly