skill-open-sourcer
Warn
Audited by Socket on Sep 5, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill's capabilities mostly match its stated purpose as a portfolio release/publishing workflow, and the data flow stays centered on the canonical GitHub repository. The main risk is proportional but meaningful transitive trust: it directs installation and verification through the `skills` CLI, which can load other skill content with the agent's permissions. No clear credential theft, covert behavior, off-purpose access, or malicious exfiltration is evident from the provided content.
Confidence: 89%Severity: 56%
Audit Metadata