chezmoi-management

Warn

Audited by Socket on Apr 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s core purpose is coherent for personal dotfile management, but it also triggers automatic installation of additional Claude skills from external repos via APM. That transitive install behavior and broad writes into ~/.claude and shell/config files make it higher risk than a plain chezmoi guide, though there is no clear evidence of credential theft or malicious exfiltration.

Confidence: 86%Severity: 68%
Audit Metadata
Analyzed At
Apr 27, 2026, 03:47 AM
Package URL
pkg:socket/skills-sh/mizchi%2Fskills%2Fchezmoi-management%2F@75292911436b9df726dd06d12971db29ac861000