engineering-advanced-skills

Warn

Audited by Socket on May 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the index file is coherent as an engineering skill bundle, but it instructs transitive installation through an unrelated third-party CLI using unpinned `npx`, which materially raises supply-chain and trust-chain risk. No direct credential harvesting or exfiltration is visible in this excerpt, so this is not confirmed malware.

Confidence: 86%Severity: 68%
Audit Metadata
Analyzed At
May 3, 2026, 10:13 AM
Package URL
pkg:socket/skills-sh/alirezarezvani%2Fclaude-skills%2Fengineering-advanced-skills%2F@e3d37814f3fa34af2cf38c6589d790eb43fb1e4d