oh-precommit-codecheck

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Purpose and capabilities mostly align: this is a pre-commit lint/auto-fix skill. The main risk is install/execution trust, because a hidden setup path downloads substantial external CodeArts tooling that cannot be verified from the provided skill text; combined with autonomous local file modification, this makes the skill suspicious but not clearly malicious.

Confidence: 82%Severity: 78%
Audit Metadata
Analyzed At
Apr 9, 2026, 07:00 AM
Package URL
pkg:socket/skills-sh/openharmonyinsight%2Fopenharmony-skills%2Foh-precommit-codecheck%2F@79d35b252e99167caac3d510c55cd020c234b326