eleventy-nunjucks

Warn

Audited by Socket on May 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the content itself is a coherent Eleventy/Nunjucks documentation skill with no credential theft or exfiltration behavior, but its install path relies on transitive skill installation from an unverified third-party repo (`t4sh/skills4sh`) without pinning or release verification. This is primarily a supply-chain and trust-chain concern, not confirmed malicious behavior.

Confidence: 89%Severity: 64%
Audit Metadata
Analyzed At
May 11, 2026, 05:52 PM
Package URL
pkg:socket/skills-sh/t4sh%2Fskills4sh%2Feleventy-nunjucks%2F@5ae2a2ab217a0ad1408cfcc13fbc570b8d3852b2