codebase-migrate

Warn

Audited by Socket on Jul 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's migration purpose is coherent, but it expands trust to the Composio CLI/service for GitHub and issue-tracker operations and uses a curl|bash installer. This looks like a legitimate automation skill with medium security risk from third-party credential forwarding and autonomous external actions, not confirmed malware.

Confidence: 84%Severity: 61%
Audit Metadata
Analyzed At
Jul 16, 2026, 09:18 AM
Package URL
pkg:socket/skills-sh/composio-community%2Fawesome-codex-skills%2Fcodebase-migrate%2F@927a2145e50681af06bf87c97c1890359b9a7f47fc1ba98e3a74c9fd31bc0eef
Security Audit — socket — codebase-migrate