files-introduction-for-ai

Warn

Audited by Socket on May 6, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core functionality is coherent for a file-indexing skill, but the installation source is not. Using a custom plain-HTTP npm registry to install code that will run automatically in pre-commit hooks and handle an API key creates a high supply-chain risk, and configurable LLM endpoints add data-flow uncertainty.

Confidence: 86%Severity: 83%
Audit Metadata
Analyzed At
May 6, 2026, 08:29 AM
Package URL
pkg:socket/skills-sh/adouwt%2Ffiles-introduction-for-ai%2Ffiles-introduction-for-ai%2F@9779072ccd9596f674c22e69622f549927a4fc96