slopship

Warn

Audited by Socket on Aug 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s stated purpose and command set are internally coherent, and it avoids embedded installers, but its core behavior depends on an unverified external slopshipper binary and optional reviewer tools with unresolved provenance. That makes the install/execution trust footprint disproportionate unless the operator independently verifies the CLI source and release chain.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
Aug 15, 2026, 08:29 AM
Package URL
pkg:socket/skills-sh/uinaf%2Fslopshipper%2Fslopship%2F@ca5b470ada7dcd56b0e48d475847b78d7a28b3c63c9bd10c279313688d75acf0
Security Audit — socket — slopship