codebase-migration

Warn

Audited by Socket on Aug 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is coherent for codebase migration, but its execution scope is aggressive. It combines full-repo ingestion with autonomous edits, test/build execution, and git commits/resets without user confirmation. No clear credential theft or external exfiltration is present, so this is not malware, but it poses medium security risk through autonomous destructive actions and prompt-injection exposure from untrusted repository content.

Confidence: 87%Severity: 66%
Audit Metadata
Analyzed At
Aug 11, 2026, 12:33 AM
Package URL
pkg:socket/skills-sh/tinh2%2Fskills-hub-registry%2Fcodebase-migration%2F@c921427a55c1ae5278c2cff31cdb5cdf7dedf1f2b0ce9f576fae1de896c47e82
Security Audit — socket — codebase-migration