apm-usage

Warn

Audited by Socket on May 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL-ja.md

SUSPICIOUS: the skill is internally consistent as an APM usage guide, but its main purpose is to install and activate other skills, which creates a significant transitive trust and supply-chain risk. No clear exfiltration or deceptive routing is shown, so this is not confirmed malware; risk comes from arbitrary skill installation, hook execution, and credential-assisted private repo access.

Confidence: 88%Severity: 64%
Audit Metadata
Analyzed At
May 11, 2026, 01:03 AM
Package URL
pkg:socket/skills-sh/mizchi%2Fskills%2Fapm-usage%2F@a8121b14a43e91b00c0abaa1422e611be74c1e69