manage-skills
Warn
Audited by Socket on May 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated purpose matches the capabilities, but the skill's footprint is high risk because it is a skill-installer/syncer for other skills across multiple agents, and it depends on an unverified `skills-manager-cli`. The biggest issue is transitive trust: it can pull skills from arbitrary git URLs and propagate them widely, so even without direct exfiltration behavior, this belongs in a high supply-chain/transitive-installation risk class.
Confidence: 89%Severity: 86%
Audit Metadata