use-skill

Warn

Audited by Socket on Sep 17, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose is inherently to fetch and execute untrusted third-party skills, which creates substantial prompt-injection and transitive-trust risk even though it uses official domains, SHA pinning, and explicit safety guardrails. It is not confirmed malware, but its actual footprint meaningfully expands the agent’s trust boundary beyond a normal utility skill.

Confidence: 92%Severity: 78%
AnomalyLOW
README.md

The supplied fragment is documentation for a remote skill installation mechanism, not evidence of malware in the fragment itself. Executing the documented npx command would create a material supply-chain risk because it downloads and may execute mutable remote code. Review and pin the package and repository contents before execution.

Confidence: 98%Severity: 55%
Audit Metadata
Analyzed At
Sep 17, 2026, 02:22 PM
Package URL
pkg:socket/skills-sh/vesely%2Fskills%2Fuse-skill%2F@eae30a1d5a349d8f54909d82e2baa8061d911a8f77e93b1277f0b62c2a65c9eb
Security Audit — socket — use-skill