auto-test-code

Warn

Audited by Socket on May 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core behavior mostly matches a code review/testing skill and uses local workspace isolation, with no strong signs of credential harvesting or covert exfiltration. Risk comes from reviewing and executing against arbitrary code with write access, plus an optional upload path to a personal GitHub repo and an unverified ~/.codex/skills path; these make it moderately risky but not malicious.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
May 11, 2026, 02:09 PM
Package URL
pkg:socket/skills-sh/huangwb8%2Fskills%2Fauto-test-code%2F@c868ec0a90787277c69b2f3698ba445d9f5fcb70