lsp-index-engineer

Fail

Audited by Socket on Mar 11, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's footprint is coherent with its stated purpose: it describes orchestrating multiple LSP clients, converting their outputs into a unified graph, and streaming updates to clients. It relies on well-known, verifiable toolchains (official language servers via npm or similar) and uses local graph storage with standard caching/endpoint patterns. No suspicious credential handling, external exfiltration, or unverifiable binaries are evident. Overall risk is low-to-medium given the performance-focused architecture, but there are no obvious security weaknesses beyond generic tooling hygiene (version pinning, access controls, and secure WebSocket configuration).

Confidence: 98%
Audit Metadata
Analyzed At
Mar 11, 2026, 09:46 AM
Package URL
pkg:socket/skills-sh/Dev-Dennis-040%2Fopenclaw-agency-skills%2Flsp-index-engineer%2F@37fade48353803c6dee3b06186122880afec3760
Security Audit — socket — lsp-index-engineer