refactor

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s core purpose and capabilities are mostly coherent for local refactoring, and there is no sign of credential harvesting or outbound exfiltration. The main concern is install/execution trust: it sources an undocumented local preflight.sh from $HOME/.codex/ship, and the publisher/provenance could not be independently verified. That makes it medium risk rather than benign, but there is not enough evidence to call it malicious.

Confidence: 86%Severity: 57%
Audit Metadata
Analyzed At
Apr 22, 2026, 11:27 AM
Package URL
pkg:socket/skills-sh/heliohq%2Fship%2Frefactor%2F@d3d6d475a7fdc832bf5b69419218a1a2358867b8
Security Audit — socket — refactor