ESLint Custom Rule Builder

Warn

Audited by Socket on Mar 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated ESLint rule-building purpose is plausible, but the main risk is the install path. This skill asks the agent to perform transitive installation from an unverified third-party skills repo via unpinned `npx`, and the publisher does not match the cited upstream ESLint project. No direct credential theft or exfiltration is shown, but install trust is insufficient.

Confidence: 90%Severity: 76%
Audit Metadata
Analyzed At
Mar 28, 2026, 06:43 PM
Package URL
pkg:socket/skills-sh/agentskillexchange%2Fskills%2Feslint-custom-rule-builder%2F@af4edb0b33574e6a4ab3f515b0b972b21528162f