dependency-vulnerability-checker

Warn

Audited by Socket on May 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The stated purpose is plausible, and there is no clear credential theft or malicious exfiltration path. However, the skill is overly generic and its Bash(npm:*) permission is broader than necessary for dependency vulnerability checking, creating medium supply-chain and execution risk without clear boundaries.

Confidence: 88%Severity: 52%
Audit Metadata
Analyzed At
May 4, 2026, 02:31 PM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus-skills%2Fdependency-vulnerability-checker%2F@228ea2e685175dde280b7d47498452541e4b685f