graphify

Warn

Audited by Socket on Aug 26, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is largely aligned with codebase graph analysis, but its footprint is broad. The main concerns are automatic third-party tool installation and high indirect prompt-injection exposure from processing untrusted external content with concurrent write/exec capabilities. No strong evidence of credential theft or overtly malicious data routing was found.

Confidence: 84%Severity: 68%
AnomalyLOW
references/query.md

The code documents legitimate local graph querying and result storage. It contains no clear malware, data exfiltration, credential theft, or destructive behavior. However, its command-construction pattern can introduce command or code injection when user questions, answers, or node names are substituted without robust escaping. This is a security design risk, not sufficient evidence of intentional malicious behavior.

Confidence: 97%Severity: 58%
Audit Metadata
Analyzed At
Aug 26, 2026, 05:58 PM
Package URL
pkg:socket/skills-sh/hosseinmirzapur%2Fopencode-skills%2Fgraphify%2F@725e28fa4b834ec2354fb3b172f84593b0d2133089243f418932412a2ef9b0d2
Security Audit — socket — graphify