double-check

Warn

Audited by Socket on Jun 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities mostly match its stated cross-provider review purpose, and the referenced verifier CLIs are generally official. The main risk is deliberate cross-provider disclosure of local code/files plus prompt-injection exposure from having another model read repo context and feed findings back into the loop; fallback installation guidance adds moderate supply-chain/transitive-trust risk.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
Jun 28, 2026, 02:16 PM
Package URL
pkg:socket/skills-sh/citypaul%2F.dotfiles%2Fdouble-check%2F@dd2f9f2acb9ec169e48dd82b960341a7e010da848b6d9df5127e649169edee5c
Security Audit — socket — double-check