code-to-pantry

Warn

Audited by Socket on Apr 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's main behavior matches its purpose, but it enables autonomous remote writes to a personal GitHub repo and references execution of GitHub-hosted code via bunx from a mutable repo. This is not confirmed malware and there is no obvious credential theft, but the public push capability and transitive GitHub execution make it a medium-risk skill that should only run with explicit user approval.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Apr 4, 2026, 01:08 AM
Package URL
pkg:socket/skills-sh/nweii%2Fagent-stuff%2Fcode-to-pantry%2F@3ee1ad33f7721f12e036f9c6fb93e7a480914e1c
Security Audit — socket — code-to-pantry