polish

Warn

Audited by Socket on Mar 23, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core purpose is coherent for a repo-polish skill, and there is no evidence of external malware delivery or credential theft, but the skill is high-trust and overly autonomous. Its main risk is transitive execution of unreviewed local skills plus automatic project-wide modifications and silent local telemetry persistence.

Confidence: 88%Severity: 71%
Audit Metadata
Analyzed At
Mar 23, 2026, 11:03 AM
Package URL
pkg:socket/skills-sh/tinh2%2Fskills-hub-registry%2Fpolish%2F@c35eed07b152dc8f9fe21f476c500664e3e2ee9e
Security Audit — socket — polish