cs-import-codebase

Warn

Audited by Socket on Jul 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose and data flows are mostly coherent for a codebase-to-SaaS mapping workflow, but it requires authenticated use of an external CodeSpring CLI/package whose provenance could not be verified from the provided evidence. Because that unverifiable tool receives account context and codebase-derived data, the security risk is high even without clear evidence of malicious intent.

Confidence: 82%Severity: 84%
Audit Metadata
Analyzed At
Jul 17, 2026, 09:22 AM
Package URL
pkg:socket/skills-sh/CodeSpringApp%2Fcodespring-skills%2Fcs-import-codebase%2F@d9e9139374b1bd309660740f0f1142f9c6740e90b654f46d263d1285dffb4f36
Security Audit — socket — cs-import-codebase