github-analysis

Warn

Audited by Socket on Apr 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s overall purpose is legitimate and mostly coherent with Magento/DDEV debugging, and several referenced tools are official. However, its most powerful operation depends on an unverifiable project-local snapshot script that connects to production, replaces the local DB, and creates admin credentials/tokens. This is high-trust, high-impact behavior that exceeds a simple GitHub analysis helper and raises medium-high security risk, though there is no clear evidence of intentional malware or credential theft.

Confidence: 81%Severity: 68%
Audit Metadata
Analyzed At
Apr 12, 2026, 11:33 AM
Package URL
pkg:socket/skills-sh/ProxiBlue%2Fclaude-skills%2Fgithub-analysis%2F@c90b5cf8b97bcdd6611d7e621f7f6d9e82b4e545
Security Audit — socket — github-analysis