graph-analysis

Warn

Audited by Socket on Apr 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The stated purpose is coherent, but the skill hides the actual backend that receives bearer tokens and performs graph building. No malware or malicious payload is shown, yet the undocumented intermediary API path creates medium security risk due to unverifiable credential and data routing.

Confidence: 82%Severity: 58%
Audit Metadata
Analyzed At
Apr 15, 2026, 01:44 PM
Package URL
pkg:socket/skills-sh/nirholas%2FXActions%2Fgraph-analysis%2F@6537afd6def49b895f5d7c8abaa45bb5770fe42e