juicebox-core-workflow-a

Warn

Audited by Socket on Mar 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and core behavior are coherent with a recruiting/search workflow, and there is no clear exfiltration or malicious payload. However, the required 'Juicebox SDK' is not concretely identified or verifiably sourced, the docs links are inconsistent with current official hosting, and the granted npm/pip execution scope is broader than the task needs. This is best classified as medium risk due to trust and provenance ambiguity, not confirmed malware.

Confidence: 83%Severity: 52%
Audit Metadata
Analyzed At
Mar 24, 2026, 04:23 PM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus-skills%2Fjuicebox-core-workflow-a%2F@7211882e96611c06b1c8320e5fb3d4ce196055be
Security Audit — socket — juicebox-core-workflow-a