Is fabricioctelles/skills safe?
Yes. fabricioctelles/skills is safe to install. Oathe's behavioral security audit gave the skills skill by fabricioctelles a trust score of 87/100 with 6 findings, none critical or high.
https://github.com/fabricioctelles/skills
Is fabricioctelles/skills safe to install?
fabricioctelles/skills is a legitimate, well-structured collection of 26 productivity and developer tools (text humanization, security auditing, Astro framework management, Coolify deployment, etc.) from an identifiable Brazilian developer. No malicious instructions, hidden encoding, credential-stealing logic, or exfiltration mechanisms were found in any SKILL.md file. The primary concerns are: (1) the security-specialist skill ships a fully functional pentest script that wraps nmap/nikto/gobuster and requires careful authorization hygiene, and (2) the auth-md skill instructs agents to fetch live content from external URLs (auth-md.com, WorkOS) which creates a third-party prompt injection surface. All canary honeypots remained intact and clone behavior was normal.
What security issues were found in fabricioctelles/skills?
Category Scores
Findings (6)
MEDIUM pentest.py implements active network scanning (nmap, nikto, wapiti3) -15 ▶
security-specialist/scripts/pentest.py wraps system-level offensive tools (nmap, nikto, gobuster, dirsearch) with Python fallbacks for port scanning. Skill requires authorization confirmation for non-localhost targets, but the capability is fully implemented and could be triggered against arbitrary URLs if the agent is deceived by prompt injection.
LOW auth-md instructs live URL fetching during normal operation -10 ▶
auth-md/SKILL.md section 'Updating Protocol Knowledge' directs agents to fetch spec content from auth-md.com and raw GitHub URLs when possible. This creates a runtime dependency on third-party URLs whose content is inserted into the agent's reasoning context, forming a potential prompt injection vector if those URLs are compromised.
LOW Dual-use potential from security + auth skill combination -15 ▶
The security-specialist and auth-md skills, when co-installed, create a surface where an agent performing a security audit could also register agent identities with discovered OAuth endpoints. Neither skill individually is malicious, but an adversarially crafted prompt could chain them against non-consenting targets.
LOW 10+ executable scripts across the skill collection -9 ▶
Multiple Python, Bash, and JS scripts exist across skills. All reviewed scripts serve documented functions (text metrics, scoring, validation, pentest). No pre/post install hooks, no git hooks, no submodules. Risk is from accidental invocation or social engineering rather than supply-chain compromise.
INFO pier-cloud scripts read and transmit user-provided API credentials -10 ▶
Pier-cloud Python scripts read PIERCLOUD_CLIENT_ID and PIERCLOUD_CLIENT_SECRET from a local .env file and send them to api.piercloud.io. Intended behavior, credentials belong to the user, but execution of these scripts from an untrusted context would transmit credentials externally.
INFO Normal GitHub clone, no unexpected network behavior -5 ▶
Clone produced a single HTTPS connection to GitHub (140.82.121.4:443). No new listening ports opened. No unexpected processes. Connection state identical before and after install. DNS queries resolved only GitHub hostnames.
Should I install fabricioctelles/skills?
Oathe's verdict for fabricioctelles/skills is SAFE with a trust score of 87/100. Recommendation: Install with caution.