deco-full-analysis
Warn
Audited by Socket on Sep 4, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s file access, git inspection, and report generation align with its stated purpose, and its data flows mostly stay local or go to expected Deco resources. The main concern is the optional remote validator: it fetches and executes third-party code with full Deno permissions via a vendor-linked URL, which is a real install/execution trust risk even without evidence of malicious intent or credential forwarding.
Confidence: 88%Severity: 58%
Audit Metadata