ESLint Auto-Fixer

Warn

Audited by Socket on Mar 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the ESLint autofix purpose is plausible and proportionate, but the actual installation path relies on transitive skill installation from an unverified third-party publisher while claiming eslint/eslint as source. No direct credential theft or exfiltration is evident, so this looks like a supply-chain and trust-boundary issue rather than confirmed malware.

Confidence: 86%Severity: 64%
Audit Metadata
Analyzed At
Mar 28, 2026, 06:43 PM
Package URL
pkg:socket/skills-sh/agentskillexchange%2Fskills%2Feslint-auto-fixer%2F@838a51d0a506dae7a15e1ca2dfb284ca9d80e919
Security Audit — socket — ESLint Auto-Fixer