li-upgrade

Warn

Audited by Socket on Apr 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s purpose and local file access are mostly coherent, but it instructs the agent to execute a transitive skill update/install from a personal GitHub repo through npx, with no verifiable release or checksum trail. This is not clear malware, but the trust chain and proactive execution behavior make it a medium-risk skill.

Confidence: 88%Severity: 64%
Audit Metadata
Analyzed At
Apr 3, 2026, 01:17 PM
Package URL
pkg:socket/skills-sh/jiangjiax%2Fli-skills%2Fli-upgrade%2F@76fe36d7c11c340226eed2b310c2fcf01f7a7af5