dfyx-code-security-auditor

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s stated purpose and capabilities are broadly coherent for a code security auditor, and the flagged curl/exec patterns are documentation examples rather than active exfiltration or command execution. However, install trust is materially inconsistent: the skill is presented as an ara.so security skill but directs users to clone an unrelated EastSword GitHub repository with no pinning, release verification, checksums, or signatures. That publisher mismatch and unpinned third-party install path create a high supply-chain risk, even though there is no clear evidence of malicious data exfiltration in the provided skill text.

Confidence: 91%Severity: 74%
Audit Metadata
Analyzed At
Sep 16, 2026, 03:19 AM
Package URL
pkg:socket/skills-sh/reason-machines%2Fsecurity-skills%2Fdfyx-code-security-auditor%2F@079a900070936ecb0f649952fd012b1e0dd09c874172cd01c4e1a63cafcd5742
Security Audit — socket — dfyx-code-security-auditor