denvig-upgrade-npm-dependencies

Warn

Audited by Socket on Apr 24, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The core purpose is coherent for a dependency-upgrade skill, but the required `denvig` CLI is not verifiably sourced from an official publisher path based on the provided evidence, which triggers a high supply-chain concern. The skill also permits autonomous git push and PR creation, and it mixes untrusted GitHub content with file modification and command execution, making the overall security risk high even without clear evidence of malware.

Confidence: 83%Severity: 78%
Audit Metadata
Analyzed At
Apr 24, 2026, 08:02 AM
Package URL
pkg:socket/skills-sh/marcqualie%2Fagent-skills%2Fdenvig-upgrade-npm-dependencies%2F@d73175a1d4283ad480c0257d4e07391738a5c7db
Security Audit — socket — denvig-upgrade-npm-dependencies