globalize-now-project-setup
Warn
Audited by Socket on Jul 9, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The skill’s behavior is mostly aligned with its stated purpose, but its trust model is weaker than ideal because it repeatedly executes an unpinned external CLI through npx and relies on that CLI’s authenticated access to Globalize and Git providers. This is better classified as suspicious/high-risk supply-chain exposure rather than malicious behavior.
Confidence: 83%Severity: 72%
Audit Metadata