career-ops

Warn

Audited by Socket on Aug 30, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
update-system.mjs

No direct evidence of classic malware (data theft/backdoor/exfiltration/obfuscation) is present in the provided fragment. The primary concern is supply-chain execution risk inherent to this updater: it fetches and checks out remote Git content into local files and then runs `npm install`, which can execute lifecycle scripts from the updated dependency set. The safety gate helps prevent accidental modification of user-owned paths but is not a cryptographic integrity guarantee, and broad empty catch blocks reduce assurance about failure handling. Overall, treat this as a high-impact updater module and verify upstream trust/pinning and install script constraints before use.

Confidence: 55%Severity: 65%
AnomalyLOW
.claude/skills/career-ops/SKILL.md

SUSPICIOUS. The skill’s purpose is coherent with job-search automation, and the available install evidence is consistent with official Playwright usage rather than an unverified payload. The main risk is not malware but capability scope: it processes untrusted web content and can perform autonomous real-world actions like application assistance and portal scanning through subagents/browser automation.

Confidence: 87%Severity: 69%
Audit Metadata
Analyzed At
Aug 30, 2026, 02:59 PM
Package URL
pkg:socket/skills-sh/black12-ag%2Fclaude-skill%2Fcareer-ops%2F@9bd5697447e0dfbe84c3b276c0f03c08f1ee20034ad4193ac056a0affba40776
Security Audit — socket — career-ops