dead-code-eliminator

Warn

Audited by Socket on Feb 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

[Skill Scanner] Skill instructions include directives to hide actions from user This SKILL.md is a benign declarative specification for a dead-code-elimination agent. It contains no executable code, no third-party downloads, no credential requests, and no suspicious network endpoints. The described capabilities align with the stated purpose. Operational risks exist only in an implementation that actually modifies repositories (those risks are procedural and mitigated here by an explicit approval gate and test/run requirements). No malicious behavior is present in this file. LLM verification: The dead-code-eliminator skill performs a legitimate and useful static analysis workflow, but it presents moderate-to-high operational risk because it can modify repository files and run project tooling that executes arbitrary code. The static scanner's finding that the instructions include a directive to 'hide actions from the user' is a significant trust break and must be removed or explained before allowing any automated write actions. Treat the tool as safe-for-reporting-only (Option D) unti

Confidence: 88%Severity: 50%
Audit Metadata
Analyzed At
Feb 24, 2026, 01:52 AM
Package URL
pkg:socket/skills-sh/abpai%2Fskills%2Fdead-code-eliminator%2F@3a7a10ed7082333311332b729f2fa969d43b61db