graphify
Warn
Audited by Socket on Jul 28, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the core Graphify CLI usage is internally consistent and uses an official PyPI package, but the skill also instructs a third-party transitive skill installation from an unrelated GitHub repo (`akillness/jeo-skills`). That extra trust chain is not proportionate to a simple CLI skill and materially increases supply-chain and agent-permission risk.
Confidence: 89%Severity: 72%
Audit Metadata