osv

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's purpose is plausible, but its actual execution path is misaligned. It presents as a Google OSV scanner interface while steering the agent to X-CMD's third-party `x osv` wrapper and optional AI/DuckDuckGo summarization, creating unnecessary supply-chain and data-flow risk beyond direct use of the official OSV scanner/API.

Confidence: 88%Severity: 74%
Audit Metadata
Analyzed At
Apr 10, 2026, 05:43 AM
Package URL
pkg:socket/skills-sh/x-cmd%2Fskill%2Fosv%2F@6fc962a621af6da6540f0d64870b50997fb871cc
Security Audit — socket — osv