dfyx-code-security-auditor
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s stated purpose and capabilities are broadly coherent for a code security auditor, and the flagged curl/exec patterns are documentation examples rather than active exfiltration or command execution. However, install trust is materially inconsistent: the skill is presented as an ara.so security skill but directs users to clone an unrelated EastSword GitHub repository with no pinning, release verification, checksums, or signatures. That publisher mismatch and unpinned third-party install path create a high supply-chain risk, even though there is no clear evidence of malicious data exfiltration in the provided skill text.
Confidence: 91%Severity: 74%
Audit Metadata