code-debug-skill
Warn
Audited by Socket on Mar 31, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s debugging purpose is plausible, but its core workflow depends on auto-running an unpinned external npm CLI (`debugsk@latest`) with unclear provenance and routing instrumented logs through that tool. The capabilities broadly match debugging, yet the install trust and added data flow make the skill higher risk than a normal documentation-only debugging guide.
Confidence: 84%Severity: 72%
Audit Metadata