ecosystem-database

Warn

Audited by Socket on Apr 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the visible skill is mostly a dispatcher that installs additional, unreviewed skills via an unseen local script. There is no direct evidence of malware or credential theft in the provided text, but the transitive installation pattern and unverifiable installer behavior create meaningful supply-chain risk.

Confidence: 83%Severity: 64%
Audit Metadata
Analyzed At
Apr 16, 2026, 06:36 AM
Package URL
pkg:socket/skills-sh/fatih-developer%2Ffth-skills%2Fecosystem-database%2F@2e9dbab4c2c5cda3ad514a08c286d7efaa3c9c25
Security Audit — socket — ecosystem-database