update-project-skills
Warn
Audited by Socket on Sep 10, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's behavior mostly matches its stated project-skill maintenance purpose, but it carries medium supply-chain risk because it executes unpinned `skills@latest` via npx and updates transitive third-party skills from recorded sources. No clear credential harvesting, covert exfiltration, or malicious mismatch is evident.
Confidence: 84%Severity: 58%
Audit Metadata