endurance-coach

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
reference/assessment.md

The visible text is benign training-plan guidance, but it recommends executing an unpinned latest npm package via `npx -y`. That creates a significant supply-chain exposure because arbitrary code from a mutable package release may run with the user’s privileges and may access Strava-related data. No direct malware behavior is demonstrated in the supplied fragment, and the package implementation is not available for verification.

Confidence: 95%Severity: 55%
Audit Metadata
Analyzed At
Sep 15, 2026, 07:22 AM
Package URL
pkg:socket/skills-sh/shiv19%2Fendurance-coach-skill%2Fendurance-coach%2F@9206bfd4ce076d722c56229b85f0d3f25154d6f44af51ce31517a915686e5283
Security Audit — socket — endurance-coach