github-codebase-search

Warn

Audited by Socket on Mar 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose broadly matches its capability, and the only declared credential is proportionate. However, instructing the agent not to inspect the script, combined with unverifiable script behavior and third-party API dependence, creates medium security risk. No strong evidence of malware or credential theft beyond expected Morph API use.

Confidence: 84%Severity: 52%
Audit Metadata
Analyzed At
Mar 28, 2026, 02:30 PM
Package URL
pkg:socket/skills-sh/trancong12102%2Fagentskills%2Fgithub-codebase-search%2F@cd73da44edeb9e86c0ad957776c7f812da528a75