skillsman-manage

Warn

Audited by Socket on May 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The stated purpose matches the behavior, but the skill is a lifecycle wrapper for installing other agent skills, so its main footprint is transitive trust in `npx skills` and whatever third-party skill sources that tool fetches. Official same-org documentation lowers maliciousness concerns, but the transitive installation model and broad downstream provenance make this a medium-high security risk rather than benign.

Confidence: 90%Severity: 78%
Audit Metadata
Analyzed At
May 8, 2026, 03:34 AM
Package URL
pkg:socket/skills-sh/YatMn%2Fskillsman%2Fskillsman-manage%2F@0e0f8fb6a774faff8819f33aecc727b247422e59
Security Audit — socket — skillsman-manage