ESLint Custom Rule Generator

Warn

Audited by Socket on Mar 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s stated purpose is benign, but its actual installation model relies on transitive trust through a third-party skill catalog that is not the claimed ESLint publisher. No clear credential theft or exfiltration is present, so this is not malware, but the provenance mismatch and skill-to-skill installation pattern make it a medium-to-high supply-chain risk.

Confidence: 89%Severity: 72%
Audit Metadata
Analyzed At
Mar 28, 2026, 06:46 PM
Package URL
pkg:socket/skills-sh/agentskillexchange%2Fskills%2Feslint-custom-rule-generator%2F@3d4a82132b17d28c46d0c321377f2ccda5d9a449