jeecg-codegen-new

Warn

Audited by Socket on Jun 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose and capabilities mostly align for local Jeecg code generation, and data stays local without obvious exfiltration. The main concerns are unverifiable bundled jars/scripts, direct DB credential use via mysql CLI, broad project file modification, and reliance on another skill; these are moderate security risks rather than confirmed malicious behavior.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 13, 2026, 09:06 AM
Package URL
pkg:socket/skills-sh/jeecgboot%2Fskills%2Fjeecg-codegen-new%2F@c41b7a11fad57f6eb2e3839187e8bd2c289e4359cd897360caa1337256b9f2c0
Security Audit — socket — jeecg-codegen-new