dependency-upgrade

Warn

Audited by Socket on Apr 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and capabilities mostly align with dependency upgrade work, and there is no obvious credential theft or exfiltration. However, it encourages unpinned execution of third-party CLIs and includes at least one likely incorrect or weakly verified external tool example, raising medium supply-chain risk.

Confidence: 87%Severity: 52%
Audit Metadata
Analyzed At
Apr 14, 2026, 06:54 PM
Package URL
pkg:socket/skills-sh/sickn33%2Fantigravity-awesome-skills%2Fdependency-upgrade%2F@4e99a64e4b4a4d695f13d9a3c5b1ea10f459d8bf
Security Audit — socket — dependency-upgrade