code-debug-skill

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s debugging purpose is plausible, but its core workflow depends on auto-running an unpinned external npm CLI (`debugsk@latest`) with unclear provenance and routing instrumented logs through that tool. The capabilities broadly match debugging, yet the install trust and added data flow make the skill higher risk than a normal documentation-only debugging guide.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Mar 31, 2026, 06:33 AM
Package URL
pkg:socket/skills-sh/abekdwight%2Fcode-debug-skills%2Fcode-debug-skill%2F@e04105cff30459f3b045a9affdcb0382b5f76b3d