code-simplifier

Warn

Audited by Socket on Mar 11, 2026

1 alert found:

Security
SecurityMEDIUM
package.json

This package runs a postinstall script that likely performs network fetches and runtime installation actions. That pattern is high-risk: the installer can execute arbitrary JS on the machine, download and run remote code, and perform telemetry or destructive actions. You should treat this as suspicious until install-skill.js is reviewed. Recommended actions: inspect the exact contents of install-skill.js and uninstall-skill.js before installing; verify any remote URLs used (ensure HTTPS and pinned checksums or signatures); run the installation in an isolated environment if needed; and look for telemetry, credential access, or execution of untrusted code.

Confidence: 70%Severity: 80%
Audit Metadata
Analyzed At
Mar 11, 2026, 08:01 AM
Package URL
pkg:socket/skills-sh/Adonis0123%2Fagent-skill-npm-boilerplate%2Fcode-simplifier%2F@7c458ca9da41dd69b4dc2ec4a30136889147ea67