technical-blog-writing

Warn

Audited by Socket on Jun 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core writing guidance is benign, but the skill’s footprint is broader than necessary. It installs/relies on external CLI tooling, encourages transitive skill installation, grants broad Bash access, consumes untrusted web research, and includes optional public posting. This is not confirmed malware, but it is over-scoped for a technical blog-writing skill and carries medium security risk.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 12, 2026, 10:27 PM
Package URL
pkg:socket/skills-sh/qu-skills%2Fskills%2Ftechnical-blog-writing%2F@b9ecd7734b868964fc8f65e6f5e71ab3ec25d0aa7f3019ded7254aedc54412e7
Security Audit — socket — technical-blog-writing