refactor-skill

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s file access and rewrite behavior fit its stated refactoring purpose, but it relies on executing an unpinned external package (`uvx skilllint@latest`) whose official provenance was not verified from the evidence, and it chains trust by loading another skill. This is not fundamentally incompatible with the skill’s purpose, but install trust is weaker than it should be.

Confidence: 85%Severity: 69%
Audit Metadata
Analyzed At
Mar 29, 2026, 08:42 AM
Package URL
pkg:socket/skills-sh/Jamie-BitFlight%2Fclaude_skills%2Frefactor-skill%2F@010ea70ed01e7704a1bae158a4bbe34d60f71764