treesitter

Warn

Audited by Socket on Aug 26, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose is coherent for a code-parsing skill, and the tool/file access is proportionate, but the auto-install path is under-specified and points to a non-official dependency trust chain. Main risk is supply-chain uncertainty, not confirmed malware or exfiltration.

Confidence: 85%Severity: 74%
AnomalyLOW
run.sh

The script is a wrapper for treesitter-tools and contains no direct evidence of malware. Its main risks are executing arbitrary commands from a sourced .env file and automatically downloading and running an unpinned GitHub repository through uvx. Pinning a reviewed commit or release, verifying hashes, and treating .env as trusted-only would reduce the risk.

Confidence: 97%Severity: 58%
Audit Metadata
Analyzed At
Aug 26, 2026, 06:02 PM
Package URL
pkg:socket/skills-sh/grahama1970%2Fagent-skills%2Ftreesitter%2F@55c03c62be9987d8246c5cb1aac74b8faa43de65
Security Audit — socket — treesitter