dependency-scan
Warn
Audited by Socket on Mar 23, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core dependency-scanning and SBOM capabilities mostly fit the stated purpose and use legitimate ecosystem tools, but the skill is overly autonomous for a repo-modifying security task, includes inconsistent commit instructions, and writes telemetry outside the project scope. Risk is mainly from autonomous real-world repo changes and broad execution, not confirmed malicious intent or credential theft.
Confidence: 87%Severity: 64%
Audit Metadata