treesitter
Warn
Audited by Socket on Aug 26, 2026
2 alerts found:
SecurityAnomalySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated purpose is coherent for a code-parsing skill, and the tool/file access is proportionate, but the auto-install path is under-specified and points to a non-official dependency trust chain. Main risk is supply-chain uncertainty, not confirmed malware or exfiltration.
Confidence: 85%Severity: 74%
Anomalyrun.sh
LOWAnomalyLOW
run.sh
The script is a wrapper for treesitter-tools and contains no direct evidence of malware. Its main risks are executing arbitrary commands from a sourced .env file and automatically downloading and running an unpinned GitHub repository through uvx. Pinning a reviewed commit or release, verifying hashes, and treating .env as trusted-only would reduce the risk.
Confidence: 97%Severity: 58%
Audit Metadata