cartography

Warn

Audited by Socket on Apr 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s purpose and local file accesses are coherent for repository mapping, and no credential or network exfiltration is described. The main issue is execution trust: it depends on an undocumented custom helper at ~/.config/opencode/skills/cartography/scripts/cartographer.py whose provenance cannot be verified from the skill, so the install/execution footprint is higher-risk than the stated task requires.

Confidence: 84%Severity: 74%
Audit Metadata
Analyzed At
Apr 14, 2026, 10:10 AM
Package URL
pkg:socket/skills-sh/alvinunreal%2Foh-my-opencode-slim%2Fcartography%2F@697dacfcbf758be22db5128c81b4cb99360e06f9