dependency-scan

Warn

Audited by Socket on Mar 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core dependency-scanning and SBOM capabilities mostly fit the stated purpose and use legitimate ecosystem tools, but the skill is overly autonomous for a repo-modifying security task, includes inconsistent commit instructions, and writes telemetry outside the project scope. Risk is mainly from autonomous real-world repo changes and broad execution, not confirmed malicious intent or credential theft.

Confidence: 87%Severity: 64%
Audit Metadata
Analyzed At
Mar 23, 2026, 11:04 AM
Package URL
pkg:socket/skills-sh/tinh2%2Fskills-hub-registry%2Fdependency-scan%2F@d639ece7a25fcce3027f3cd5746a3e62d4ff4c28
Security Audit — socket — dependency-scan