Big News: Socket raises $60M Series C at a $1B valuation to secure software supply chains for AI-driven development.Announcement
Sign In

Skill: Supply chain risk

Severity

Medium

Short Description

AI agent skill installs unpinned dependencies, references external scripts, or directs agents to download software from untrusted sources.

Suggestion

Review the skill's code and behavior carefully. Ensure the detected patterns are intentional and safe before allowing this skill to run.