threejs

Warn

Audited by Socket on Sep 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The catalogue entry is lightweight and does not itself steal data or execute code, but it mainly redirects trust to an external upstream bundle, and the reported mismatch between CloudAI-X and pinkforest install guidance weakens provenance. Low direct malware evidence, moderate security risk from transitive installation and unclear upstream ownership consistency.

Confidence: 89%Severity: 62%
Audit Metadata
Analyzed At
Sep 24, 2026, 04:24 AM
Package URL
pkg:socket/skills-sh/skeletorflet%2Fopencode-supreme-setup%2Fthreejs%2F@5102dc3ae2f4f781c3ca31def3d7efaf79c2ed06cc1c73d364a8a1edb2b76df8
Security Audit — socket — threejs