graphify

Warn

Audited by Socket on Jul 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core Graphify CLI usage is internally consistent and uses an official PyPI package, but the skill also instructs a third-party transitive skill installation from an unrelated GitHub repo (`akillness/jeo-skills`). That extra trust chain is not proportionate to a simple CLI skill and materially increases supply-chain and agent-permission risk.

Confidence: 89%Severity: 72%
Audit Metadata
Analyzed At
Jul 28, 2026, 01:52 PM
Package URL
pkg:socket/skills-sh/akillness%2Fjeo-skills%2Fgraphify%2F@1cedee9cd794886020d5c8ded38bff7aaf7ab279817807fbea20255ebd38bf7b
Security Audit — socket — graphify