graphify

Warn

Audited by Socket on Aug 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core graph-building behavior matches the stated purpose, and the package source appears official, but the skill’s footprint is broad: silent package installation, arbitrary file/URL ingestion, parallel subagent processing of untrusted content, persistent local modifications, and optional credentialed Neo4j push. This is better viewed as a medium-risk powerful automation skill than malware.

Confidence: 87%Severity: 61%
Audit Metadata
Analyzed At
Aug 15, 2026, 03:25 AM
Package URL
pkg:socket/skills-sh/khanhhuyenngo985-sys%2Fcharacter-scene-design-skills%2Fgraphify%2F@2c56da076728731d37e4118782b9f79f0083091d29c65573d83b56c268b1fb89
Security Audit — socket — graphify