react-grab

Warn

Audited by Socket on Apr 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The stated purpose is coherent, but the install and execution trust story is weaker than it should be: the skill tells users to execute mutable remote package code (`npx ...@latest`), load runtime code from unpkg, and install broad agent integrations, while the key package name differs from the published project name. That is not enough to call it malicious, but it is enough to treat the skill as medium-to-high supply-chain risk until publisher/package ownership and script behavior are independently verified.

Confidence: 80%Severity: 66%
Audit Metadata
Analyzed At
Apr 16, 2026, 08:00 AM
Package URL
pkg:socket/skills-sh/akillness%2Foh-my-skills%2Freact-grab%2F@3b4bd9fa15b0262bd6226c0067d602e711ab7f4b