ESLint Custom Rule Builder
Warn
Audited by Socket on Mar 28, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated ESLint rule-building purpose is plausible, but the main risk is the install path. This skill asks the agent to perform transitive installation from an unverified third-party skills repo via unpinned `npx`, and the publisher does not match the cited upstream ESLint project. No direct credential theft or exfiltration is shown, but install trust is insufficient.
Confidence: 90%Severity: 76%
Audit Metadata