codebase-text-report

Warn

Audited by Socket on Sep 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's behavior mostly matches its stated purpose, but it combines dynamic third-party tool execution (`npx`) with ingestion of untrusted remote codebases and grants Bash+Write capabilities during analysis. No clear credential theft or exfiltration path is described, so this is better classified as a medium/high security-risk skill rather than malware.

Confidence: 82%Severity: 68%
Audit Metadata
Analyzed At
Sep 3, 2026, 10:20 AM
Package URL
pkg:socket/skills-sh/anentrypoint%2Fgitoutput%2Fcodebase-text-report%2F@57d95b0d7627a0ffc1459a2e3cb4da216f71e63c8006b454e347c09101a254d5
Security Audit — socket — codebase-text-report