github-trending

Warn

Audited by Socket on May 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose and data flow are coherent for fetching GitHub Trending, and it does not request credentials or access sensitive files. The main concern is supply-chain trust: it tells the agent to auto-install and execute a third-party npm CLI from a personal publisher via `npx --yes`, which is broader trust than necessary for a simple public-data lookup.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
May 12, 2026, 09:37 AM
Package URL
pkg:socket/skills-sh/zjy365%2Fgh-explorer%2Fgithub-trending%2F@bb27bc13b5af189635727ca886382325c0b02d7e