project-audit

Warn

Audited by Socket on Apr 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The stated purpose is coherent for a code-audit skill, and the described file access/write behavior is mostly proportionate. However, the core execution dependency is inconsistent: the skill references vibeco audit, while the nearest verifiable public tool is vibecop with different documented commands. That mismatch weakens install trust and makes the actual runtime footprint unverifiable. No clear credential harvesting or exfiltration is shown, so this is not confirmed malware, but it carries medium risk due to the unresolved supply-chain ambiguity and agent security-scanning capability.

Confidence: 84%Severity: 63%
Audit Metadata
Analyzed At
Apr 24, 2026, 05:45 PM
Package URL
pkg:socket/skills-sh/vibeeval%2Fvibecosystem%2Fproject-audit%2F@2c70ec714f239def2e32bd01223ef25f2a15a6ab
Security Audit — socket — project-audit