ai-scoring

Warn

Audited by Socket on May 5, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s main scoring guidance is coherent and benign, but it includes explicit transitive skill-install instructions using unpinned `npx skills add` against a third-party repository. That makes the install/data-flow footprint broader than necessary for a scoring guide and raises medium security concern despite no direct malware behavior in the skill content itself.

Confidence: 89%Severity: 62%
Audit Metadata
Analyzed At
May 5, 2026, 04:33 PM
Package URL
pkg:socket/skills-sh/lebsral%2FDSPy-Programming-not-prompting-LMs-skills%2Fai-scoring%2F@84c8a1a4e9226edf92cd6961d94857bd498f677c