dependency-confusion
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS/HIGH-RISK. The skill is internally coherent as a dependency-confusion red-team playbook, but it equips an AI agent with offensive supply-chain testing steps, transitive routing to another skill, third-party security tooling, and callback-based execution proofs. File/config references are mostly documentation, not direct credential theft, yet the overall capability is high risk because it enables exploit-style actions beyond passive review.
Confidence: 91%Severity: 82%
Audit Metadata