angular-best-practices-signalstore

Warn

Audited by Socket on Mar 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

Overall, the manifest appears to be a benign metadata/installation guide for a legitimate-sounding add-on to an Angular best-practices skill. The primary risk vector is the transitive installation pattern (npx skills add ...), which should be reviewed in environments with strict dependency controls to ensure the target repository remains trustworthy and that pinned versions are used where possible. Otherwise, the footprint aligns with a skill intended to augment an existing toolchain and does not exhibit explicit malicious behavior in the fragment provided.

Confidence: 70%Severity: 65%
Audit Metadata
Analyzed At
Mar 2, 2026, 01:30 PM
Package URL
pkg:socket/skills-sh/alfredoperez%2Fangular-best-practices%2Fangular-best-practices-signalstore%2F@6dc911ab41505b8ec535149b821bc0c1ecb056af