java

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

BENIGN in purpose and data flow, but SUSPICIOUS on install trust: the monitoring scope is proportionate and no credential harvesting or exfiltration is evident, yet the required ibmi CLI is not verified by the supplied evidence and does not cleanly match the official IBM-documented install path that was found. This raises medium-high supply-chain risk rather than malware evidence.

Confidence: 86%Severity: 72%
Audit Metadata
Analyzed At
Apr 1, 2026, 02:35 PM
Package URL
pkg:socket/skills-sh/ajshedivy%2Fibmi-agent-skills%2Fjava%2F@aeb26b23f7e6d310ecf8650db77d5baa020a3e77