apm-usage

Warn

Audited by Socket on Apr 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is internally consistent as an APM usage guide, but its main purpose is to install and activate other skills, which creates a significant transitive trust and supply-chain risk. No clear exfiltration or deceptive routing is shown, so this is not confirmed malware; risk comes from arbitrary skill installation, hook execution, and credential-assisted private repo access.

Confidence: 88%Severity: 64%
Audit Metadata
Analyzed At
Apr 20, 2026, 08:34 AM
Package URL
pkg:socket/skills-sh/mizchi%2Fchezmoi-dotfiles%2Fapm-usage%2F@ff8a326988c39c39c028339a6bdc248dc1bbf208
Security Audit — socket — apm-usage