npm-package

Warn

Audited by Socket on May 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core package-template guidance is coherent and largely benign, but the skill includes two disproportionate agent-specific risks: transitive installation of another skill via the `skills` CLI and runtime fetching of mutable remote README content that can steer agent behavior. No evidence of credential theft or overt malware, but the trust boundary is broader than a simple npm package template needs.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
May 12, 2026, 08:32 AM
Package URL
pkg:socket/skills-sh/remorses%2Fkimaki%2Fnpm-package%2F@4867cbd200cbab766b31271fd9f5081608f5eb43