enable-quality-gate

Fail

Audited by Socket on Mar 3, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill outline aligns with enabling mise/hk quality gates and migrating hooks but relies on high-risk download-and-execute installation patterns and remote artifact fetching without explicit integrity validation. This creates notable supply-chain and execution risks. Treat as SUSPICIOUS-to-HIGH-RISK until installers are pinned, signed, and verified; enforce explicit integrity checks, restrict or document trusted sources, and prefer non-pipe-to-shell installation methods where possible.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 3, 2026, 07:42 AM
Package URL
pkg:socket/skills-sh/bitsoex%2Fbitso-java%2Fenable-quality-gate%2F@736f4906d928658066d71b133f67ea8a5054baec