update-everything

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

Benign with elevated risk due to the use of external metadata endpoints for toolchain alignment (external JSON/XML feeds). No credential harvesting, no autonomous destructive actions, and the workflow adheres to a well-scoped dependency-update use case. The primary security consideration is ensuring external toolchain metadata are trusted and validated (checksums, signatures) where possible, and that any automated toolchain changes are reviewable in PRs. Overall, the skill footprint is coherent with its stated purpose and is proportionate in scope; maintain caution around external alignment sources and ensure proper vetting of any automated commit/push behavior.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 10:13 PM
Package URL
pkg:socket/skills-sh/a2f0%2Ftearleads%2Fupdate-everything%2F@8838186173cddb386b82c5613e4e68ce13136f64