ESLint Rule Analyzer and Fixer

Warn

Audited by Socket on Mar 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The stated ESLint-analysis purpose is coherent, and no credential harvesting or exfiltration is evident, but the installation model is a transitive skill install from third-party registries (`npx skills add` / `clawhub install`) whose trust relationship to `eslint/eslint` is not established. The main risk is supply-chain and inherited agent-permission exposure, not confirmed malware.

Confidence: 86%Severity: 68%
Audit Metadata
Analyzed At
Mar 28, 2026, 06:44 PM
Package URL
pkg:socket/skills-sh/agentskillexchange%2Fskills%2Feslint-rule-analyzer-and-fixer%2F@1c6584c4a4295b3ed2f2e11fe24f890c7bd3df28