skill-open-sourcer

Warn

Audited by Socket on Sep 5, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities mostly match its stated purpose as a portfolio release/publishing workflow, and the data flow stays centered on the canonical GitHub repository. The main risk is proportional but meaningful transitive trust: it directs installation and verification through the `skills` CLI, which can load other skill content with the agent's permissions. No clear credential theft, covert behavior, off-purpose access, or malicious exfiltration is evident from the provided content.

Confidence: 89%Severity: 56%
Audit Metadata
Analyzed At
Sep 5, 2026, 06:08 AM
Package URL
pkg:socket/skills-sh/zjp1997720%2Fzhijian-skills%2Fskill-open-sourcer%2F@81fc3b67e0f9a99219938de932f8d30de21fd57ac3b326a98a2666df9dde3059
Security Audit — socket — skill-open-sourcer