dkod

Warn

Audited by Socket on Apr 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is broadly coherent with its stated purpose of parallel code editing via dkod, and the remote MCP install/auth pattern matches Anthropic’s documented workflow. However, it asks the agent to add a third-party MCP service/plugin, sends repository data to dkod-controlled endpoints, and can push PRs; combined with the unverified plugin publisher relationship, this makes it medium risk rather than benign.

Confidence: 81%Severity: 61%
Audit Metadata
Analyzed At
Apr 12, 2026, 04:44 PM
Package URL
pkg:socket/skills-sh/dkod-io%2Fdkod-plugin%2Fdkod%2F@384646a7ede78f8571c95c9e4721012f8b7b87ac