dx

Warn

Audited by Socket on Mar 23, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core audit behavior is coherent and uses only local project files, but the skill overreaches by forcing autonomous execution, automatically invoking other skills under --fix, and silently writing telemetry outside the repository. No strong malware or credential-theft signals are present, but the transitive trust chain and autonomous file-changing behavior make it higher risk than a normal audit skill.

Confidence: 89%Severity: 74%
Audit Metadata
Analyzed At
Mar 23, 2026, 11:04 AM
Package URL
pkg:socket/skills-sh/tinh2%2Fskills-hub-registry%2Fdx%2F@63a4f113aa413891d284b12969380039872f976b
Security Audit — socket — dx