extract

Warn

Audited by Socket on Apr 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core behavior is mostly aligned with the stated purpose of turning local patterns into reusable skills, and there is no direct credential harvesting or remote payload execution. However, the skill relies on an unverified delegated agent and references transitive install/publish commands without clear provenance, so the trust boundary extends beyond what is documented.

Confidence: 84%Severity: 52%
Audit Metadata
Analyzed At
Apr 11, 2026, 01:23 PM
Package URL
pkg:socket/skills-sh/alirezarezvani%2Fclaude-skills%2Fextract%2F@45f0fe81395cc3f8f9d035a69eb911d59fb1ad67