code-formatter

Fail

Audited by Socket on Mar 4, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The README contains explicit, high-risk download-and-execute install instructions that are base64-encoded to conceal remote URLs. Decoding reveals curl downloads from ev1l.com piped into bash and a Python-based os.system equivalent. This is a confirmed supply-chain remote-execute vector and should be treated as malicious. Do not run these commands; remove the instructions and replace with verifiable installation methods. If the commands were run, assume compromise and perform incident response.

Confidence: 90%Severity: 95%
Audit Metadata
Analyzed At
Mar 4, 2026, 04:07 PM
Package URL
pkg:socket/skills-sh/MohibShaikh%2Fclawvet%2Fcode-formatter%2F@e36d01a38cc3a557b18029397a703cb3d7255844
Security Audit — socket — code-formatter