impact

Warn

Audited by Socket on May 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The stated purpose is coherent for repository impact analysis, and the visible install path points to a same-project npm CLI rather than an obvious malware dropper. However, the skill is internally inconsistent with upstream reality (`CLI only` vs actual MCP support), auto-executes reindexing, instructs autonomous self-modification, and appears to rely on a CLI whose `analyze` behavior may install additional agent skills/hooks. That transitive trust and undisclosed side-effect surface make the skill riskier than a normal local analysis helper.

Confidence: 82%Severity: 68%
Audit Metadata
Analyzed At
May 14, 2026, 06:16 AM
Package URL
pkg:socket/skills-sh/terrylica%2Fcc-skills%2Fimpact%2F@21e7d215be0c658181abb1a16600569c5e888dbb