denvig-upgrade-npm-dependencies
Warn
Audited by Socket on Apr 24, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The core purpose is coherent for a dependency-upgrade skill, but the required `denvig` CLI is not verifiably sourced from an official publisher path based on the provided evidence, which triggers a high supply-chain concern. The skill also permits autonomous git push and PR creation, and it mixes untrusted GitHub content with file modification and command execution, making the overall security risk high even without clear evidence of malware.
Confidence: 83%Severity: 78%
Audit Metadata