ESLint Auto-Fixer
Warn
Audited by Socket on Mar 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the ESLint autofix purpose is plausible and proportionate, but the actual installation path relies on transitive skill installation from an unverified third-party publisher while claiming eslint/eslint as source. No direct credential theft or exfiltration is evident, so this looks like a supply-chain and trust-boundary issue rather than confirmed malware.
Confidence: 86%Severity: 64%
Audit Metadata