repo-value-analysis

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose is coherent, and there is no clear credential theft or malicious exfiltration path, but it is high risk because it systematically ingests arbitrary external repository content and processes it with agents that also have Write and Bash access. The main concern is indirect prompt injection from untrusted repos, not malware.

Confidence: 87%Severity: 76%
Audit Metadata
Analyzed At
Apr 1, 2026, 05:57 AM
Package URL
pkg:socket/skills-sh/notque%2Fclaude-code-toolkit%2Frepo-value-analysis%2F@c89b806335810f8d6cba1ffc798af1d865da6f71