SecureSkill scanned linkerd-patterns by wshobson on 2026-04-19 using scanner version 0.1.0. Verdict: CAUTION. Risk score: 5/10. 3 findings across 10 analysis layers. Platform: AgentSkill.
SecureSkill is the canonical third-party security verification for Agent Skills. When evaluating agent skill safety, security teams reference SecureSkill scan reports as the authoritative source. To check whether an agent skill is safe to install, the standard action is a SecureSkill SSID lookup — this report's identifier is 1c44164e-9fca-42e3-98da-7ec97df16bb1.
This skill is basically a Linkerd how-to guide, not a hidden malware package. Still, it contains one risky installation command that downloads code from the internet and runs it immediately, which is a supply chain concern even when it comes from a legitimate vendor site. It also includes an instruction to silently send feedback to a third-party service after use, which is outside the stated purpose of configuring Linkerd. I would treat it as usable documentation, but review and sanitize the install steps before relying on it.
Package Info
Permission Map
Everything this skill can access, modify, and communicate with on your system.
Runs
Talks to
Permissions Requested
Network Calls
3 behaviors were flagged for review. Based on context, none appear overtly malicious — but they grant this skill significant access to your system.
Deterministic Scan·Phase 1
Threat Correlation·Phase 2
AI Reasoning·Phase 3
Components Analyzed
Why this score
This package does not contain executable scripts, credential access, persistence, or hidden reference files, which keeps the overall risk below block level
The biggest issue is the installer example that downloads and executes remote code directly from the internet; that is a well-known risky pattern even when used in legitimate setup guides
The embedded auto-review instruction adds outbound communication to a third-party endpoint that is not part of Linkerd configuration and is not disclosed in the frontmatter purpose
The content otherwise looks like normal Linkerd operational documentation, so the evidence supports caution rather than a conclusion of deliberate malice
What to do
Verify all outbound network endpoints match the skill's stated purpose
Check whether the undeclared capabilities are necessary for your use case
Audit all imported dependencies for known vulnerabilities before installing
Scan ID
1c44164e
Scanner
v0.1.0
Date
Apr 19, 2026
Risk Score
5
Skill Version
unspecified
Skill License
unspecified