cs-import-codebase
Warn
Audited by Socket on Jul 17, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s purpose and data flows are mostly coherent for a codebase-to-SaaS mapping workflow, but it requires authenticated use of an external CodeSpring CLI/package whose provenance could not be verified from the provided evidence. Because that unverifiable tool receives account context and codebase-derived data, the security risk is high even without clear evidence of malicious intent.
Confidence: 82%Severity: 84%
Audit Metadata