pixi

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose is broadly consistent with package/environment management, but it is framed as Pixi while actually steering the agent to the x-cmd wrapper and its auto-install/mirror logic. This is not clearly malicious, yet the extra trust layer and third-party mirror routing make the footprint riskier than a normal official Pixi guide.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Apr 10, 2026, 05:43 AM
Package URL
pkg:socket/skills-sh/x-cmd%2Fskill%2Fpixi%2F@dee280d577c334342e5857703e4b3e283e6f83c8