explain-code

Warn

Audited by Socket on May 5, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose is mostly aligned with code explanation, but the skill broadens scope by requiring a second skill, executing `npx` tooling, and ingesting arbitrary web content with local write capability. No clear malware or credential theft is present, but the transitive-skill trust chain and prompt-injection exposure make it a medium-risk skill.

Confidence: 88%Severity: 58%
Audit Metadata
Analyzed At
May 5, 2026, 04:39 PM
Package URL
pkg:socket/skills-sh/flora131%2Fatomic%2Fexplain-code%2F@ab5b1f14ecc556996be9b938abf975e6e3aa57e4