backend-integration

Warn

Audited by Socket on Apr 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's stated backend-migration purpose is coherent with its capabilities, and the clone source appears to be the publisher's same-org GitHub repo rather than an arbitrary payload host. The main concern is the required replacement of AGENTS.md from that external repo, which imports new agent instructions and creates a transitive trust/instruction-injection path; this raises security risk above benign even without clear malicious behavior.

Confidence: 85%Severity: 61%
Audit Metadata
Analyzed At
Apr 14, 2026, 04:14 PM
Package URL
pkg:socket/skills-sh/customware-ai%2Fskills%2Fbackend-integration%2F@0f5237187670f77cfba9489f4ae9877c41083e90