javascript-sdk

Warn

Audited by Socket on Jun 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core SDK documentation is largely coherent and uses standard npm distribution, but the skill is broadened by explicit transitive skill-install instructions and agent/tool patterns that expand trust beyond a simple JavaScript SDK. The main concern is scope creep and external skill installation, not confirmed malware.

Confidence: 87%Severity: 62%
Audit Metadata
Analyzed At
Jun 19, 2026, 02:15 AM
Package URL
pkg:socket/skills-sh/halt-catch-fire%2Fskills%2Fjavascript-sdk%2F@7d428b467344dc4e01573a9c8159b873a525a82fd2dd7b237fed3297d24b6456
Security Audit — socket — javascript-sdk