sjskills

Warn

Audited by Socket on Sep 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose and capabilities are internally coherent for skill-state reconciliation, and there is no clear credential harvesting or third-party proxying. However, it depends on an unverified local `sjskills` executable and authorizes broad project/global mutations through that opaque CLI, which triggers high supply-chain risk even though malicious intent is not confirmed.

Confidence: 84%Severity: 82%
Audit Metadata
Analyzed At
Sep 8, 2026, 11:18 AM
Package URL
pkg:socket/skills-sh/sjunepark%2Fagent-scripts%2Fsjskills%2F@cb7b1a6279f6b1a08b9bcb6b3bf3384ff4ff0235dcf5aa9654cd7de4fccc3939
Security Audit — socket — sjskills