octocode-install

Warn

Audited by Socket on Jun 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose matches its installer behavior, but it relies on unpinned npx execution, forwards GitHub credentials to third-party package code, and performs transitive skill installation. This is more consistent with a risky installer than overt malware; use only if the Octocode npm packages and publisher are independently verified.

Confidence: 79%Severity: 67%
Audit Metadata
Analyzed At
Jun 18, 2026, 04:45 AM
Package URL
pkg:socket/skills-sh/bgauryy%2Foctocode%2Foctocode-install%2F@2ab32d8c5ec0c96c7729f6eef1510520bab302389e65dd976ef123ef2e0fc40d
Security Audit — socket — octocode-install