find-skills

Warn

Audited by Socket on May 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The capability fits a skill-discovery purpose, but the trust chain is not coherent with the official ecosystem: it replaces the official Vercel skills CLI with a personal-repo mcphub installer delivered via curl|sh, then encourages transitive installation of arbitrary third-party skills. No direct credential theft is shown, but the supply-chain and inherited-permissions risks are high.

Confidence: 91%Severity: 84%
Audit Metadata
Analyzed At
May 13, 2026, 04:30 AM
Package URL
pkg:socket/skills-sh/vaayne%2Fmcphub%2Ffind-skills%2F@9357dce8156dfb547e4ba0b046513c2e51c30b84
Security Audit — socket — find-skills