typescript-expert

Fail

Audited by Socket on Mar 1, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

Overall, the code fragment is a coherent, benign skill specification intended to configure an AI agent for TypeScript expertise. There are no embedded credentials, external data exfiltration paths, or executable payloads. The primary risk would arise if the agent were to autonomously execute the listed shell commands or install/build tools without explicit user consent, which would be an operational risk rather than an embedded security threat. Ensure strict user consent and execution guards when turning these guidelines into automated actions.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 1, 2026, 08:52 PM
Package URL
pkg:socket/skills-sh/baotoq%2Fmicro-commerce%2Ftypescript-expert%2F@15ac025cd232cd16780b89f8baca92cfff4d0855
Security Audit — socket — typescript-expert