setup-skilly
Warn
Audited by Socket on Aug 31, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s purpose is coherent, but its trust model is weak: it executes a GitHub-hosted CLI via npx, bootstraps ongoing transitive skill installation/sync, and enables automatic PR-generating workflows. The main concern is supply-chain and inherited trust breadth rather than confirmed malicious behavior.
Confidence: 83%Severity: 76%
Audit Metadata