day4-wrap-and-analyze

Warn

Audited by Socket on Mar 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The provided artifact is a high-level instructional skill guide for a multi-block training workflow that uses public registry installations to fetch components. Its footprint is coherent with a teaching/learning objective and does not exhibit credential harvesting, exfiltration, or hidden payloads. The main security considerations are the standard risks associated with executing npm/npx commands from public registries (trust in the registry, integrity of packages, and version management). Overall, the artifact is BENIGN with MEDIUM security risk due to supply-chain considerations of external installations, but not malicious in behavior as presented.

Confidence: 70%Severity: 65%
Audit Metadata
Analyzed At
Mar 4, 2026, 11:32 AM
Package URL
pkg:socket/skills-sh/ai-native-camp%2Fcamp-2%2Fday4-wrap-and-analyze%2F@325f941a5e9b3a55007269ee1d949c5e2bfda786