npm-publish

Pass

Audited by Socket on Feb 17, 2026

Checks
Malicious behaviorInjection, exfiltration, untrusted installs
Security concernsCredential exposure, tool/trust exploitation
Code obfuscationHidden or obfuscated code
Suspicious patternsReconnaissance, excessive autonomy, resource use
Audit Metadata
Analyzed At
Feb 17, 2026, 06:22 PM
Package URL
pkg:socket/skills-sh/autumnsgrove%2Fgroveengine%2Fnpm-publish%2F@4e54c3e651a4d5f74ffea3f4e7f7c87e97914aea