dex-update

Warn

Audited by Socket on May 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core update behavior fits the stated purpose, but the footprint is broader than a simple updater. Automatically executing freshly pulled scripts, running package installs, modifying live config, and silently enabling background automations create a high trust burden and elevated security risk even without clear evidence of credential theft or overt malware.

Confidence: 84%Severity: 76%
Audit Metadata
Analyzed At
May 20, 2026, 12:43 AM
Package URL
pkg:socket/skills-sh/davekilleen%2FDex%2Fdex-update%2F@d92ba5afcc189b9529faec945c661fbea7f68158
Security Audit — socket — dex-update