shortcut

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose mostly matches its Shortcut-management actions, but trust is weakened by dependence on a community CLI, a mismatched npm install instruction, and credential forwarding through third-party client code. There is no clear evidence of malware or off-platform exfiltration, but the install/auth chain is not fully consistent with official Shortcut tooling.

Confidence: 84%Severity: 64%
Audit Metadata
Analyzed At
Apr 1, 2026, 08:37 AM
Package URL
pkg:socket/skills-sh/hefgi%2Fskills%2Fshortcut%2F@55e1e50158810e58221c7f99d3bdec59f721b39f
Security Audit — socket — shortcut