codebase-exploration

Warn

Audited by Socket on May 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core behavior is consistent with codebase onboarding, but the skill asks the agent to install another third-party skill via `npx skills add`, creating transitive trust, and it combines untrusted repository ingestion with execute/edit capabilities. No direct credential theft or exfiltration is shown, so this is better classified as medium-risk vulnerable rather than malicious.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
May 16, 2026, 03:34 AM
Package URL
pkg:socket/skills-sh/ChristopherAlphonse%2Fcalphonse-skills%2Fcodebase-exploration%2F@52b61341319f70fb375906237f6dc1859cf1fa82