codependix-export

Warn

Audited by Socket on Sep 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s behavior is largely coherent with its stated purpose and stays local to workspace analysis, with no clear credential theft or exfiltration. The main risk is install/execution trust: 'npx codependix' may download and run an npm package whose public provenance was not verified, so the skill carries medium supply-chain risk despite otherwise proportionate scope.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Sep 3, 2026, 10:39 PM
Package URL
pkg:socket/skills-sh/jimmypaolini%2Fcodebase%2Fcodependix-export%2F@08c4b494c56761e0129e7573a9dc9cfb4364e1b167eec1013af9cb14227efc34
Security Audit — socket — codependix-export