codedbpro
Warn
Audited by Socket on Jul 22, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s purpose matches its code-editing capabilities, but it requires a broad-power external daemon whose official install path uses unpinned `curl|bash` and whose Pro binary provenance is not clearly verifiable. No direct credential theft or overt exfiltration is shown, but the black-box daemon and out-of-repo file access make the trust footprint disproportionate enough to rate high security risk.
Confidence: 84%Severity: 78%
Audit Metadata