dep-audit

Warn

Audited by Socket on Apr 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose is legitimate, but the skill is overprivileged and delegates execution to repo-local shell scripts and potentially remote npx packages. Data flow is mostly consistent with dependency auditing, yet the combination of wildcard bash/npx permissions, local script execution, and auto-fix behavior makes the skill higher risk than its narrow purpose suggests.

Confidence: 87%Severity: 62%
Audit Metadata
Analyzed At
Apr 20, 2026, 07:26 PM
Package URL
pkg:socket/skills-sh/sd0xdev%2Fsd0x-dev-flow%2Fdep-audit%2F@591c80b3b1e08a5d4e5cd6d8861122e9dfb63c42
Security Audit — socket — dep-audit