project-analyzer

Warn

Audited by Socket on Mar 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The stated purpose is coherent with repository reading and document generation, and there is no explicit credential harvesting or exfiltration. However, the skill requires an unspecified sub-skill and undocumented prompt files, creating a meaningful transitive trust and untrusted-content risk that is disproportionate to a fully reviewable documentation workflow.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Mar 28, 2026, 12:47 PM
Package URL
pkg:socket/skills-sh/ForceInjection%2Fawesome-skills%2Fproject-analyzer%2F@6972106df9ece163c378a2a4d84746aac3b3f35f
Security Audit — socket — project-analyzer