codependix-export
Warn
Audited by Socket on Sep 3, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s behavior is largely coherent with its stated purpose and stays local to workspace analysis, with no clear credential theft or exfiltration. The main risk is install/execution trust: 'npx codependix' may download and run an npm package whose public provenance was not verified, so the skill carries medium supply-chain risk despite otherwise proportionate scope.
Confidence: 84%Severity: 58%
Audit Metadata