codedbpro

Warn

Audited by Socket on Jul 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose matches its code-editing capabilities, but it requires a broad-power external daemon whose official install path uses unpinned `curl|bash` and whose Pro binary provenance is not clearly verifiable. No direct credential theft or overt exfiltration is shown, but the black-box daemon and out-of-repo file access make the trust footprint disproportionate enough to rate high security risk.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
Jul 22, 2026, 06:36 AM
Package URL
pkg:socket/skills-sh/deligoez%2Fskills%2Fcodedbpro%2F@c7b23de6c02dec7a5c7ab66b0588f76630973937658420713a6b2da1b64c0e03
Security Audit — socket — codedbpro