command-code

Warn

Audited by Socket on Jul 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is coherent with its stated purpose, and the installer path appears same-org and npm-based, but its actual footprint is high-risk because it centers on launching an external coding agent in fully unsupervised `--yolo` mode, can ingest untrusted GitHub issue content, and exposes a transitive skill-install path. This is better classified as a risky orchestration skill than malware.

Confidence: 90%Severity: 74%
Audit Metadata
Analyzed At
Jul 31, 2026, 01:36 AM
Package URL
pkg:socket/skills-sh/duyet%2Fclaude-plugins%2Fcommand-code%2F@d42842d0f327dbd3b0e2eacd8692363b9d2ad38e850719eccc36e6320a8859c2
Security Audit — socket — command-code