skillsman-init

Warn

Audited by Socket on May 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The stated purpose matches its behavior as a skill installer, but its core action is transitive installation of other agent skills through an unverified `skillsman` CLI, including a local binary fallback with no established provenance. User confirmation helps, but the unverifiable installer and inherited trust chain make the skill high risk.

Confidence: 89%Severity: 84%
Audit Metadata
Analyzed At
May 7, 2026, 11:10 AM
Package URL
pkg:socket/skills-sh/YatMn%2Fskillsman%2Fskillsman-init%2F@ebec27a81655d57a3f715c2cdad342260806a3ee
Security Audit — socket — skillsman-init