scratch

Warn

Audited by Socket on Apr 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core local exploration behavior is broadly consistent with the stated purpose, but the skill carries medium execution risk because it tells the agent to run arbitrary project code and includes a transitive self-update path through a third-party CLI (`npx skills update scratch`) unrelated to the publisher. No direct credential harvesting or clear exfiltration is present, so this is not malware, but it is higher-risk than a pure documentation skill.

Confidence: 88%Severity: 58%
Audit Metadata
Analyzed At
Apr 14, 2026, 05:02 AM
Package URL
pkg:socket/skills-sh/abpai%2Fskills%2Fscratch%2F@851c17478522336af231aaadc8a432eff1c18f9a
Security Audit — socket — scratch