sync-template

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's stated purpose (syncing a downstream project with a template via discovery, package updates, diffing, planning, and execution) is broadly coherent with the described steps. The footprint is proportionate for a developer tooling workflow but introduces notable supply-chain and transitive-trust risk due to reliance on unverifiable binaries and loading of an external skill. Data flows are mostly internal to the developer environment, with no explicit credential exfiltration, which keeps the risk at a moderate level. The presence of download/executable steps (opensrc opensrc:use and external skill delegation) warrants treating this as SUSPICIOUS to HIGH risk in strict security postures until provenance and verification mechanisms (signatures, checksums, pinned versions, and lockfiles) are demonstrated. Overall securityRisk should be considered MEDIUM-HIGH (0.55–0.65) with malware near zero unless further evidence of malicious intent is found.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 05:48 AM
Package URL
pkg:socket/skills-sh/blogic-cz%2Fblogic-marketplace%2Fsync-template%2F@cd63f3ad5ec0ed0a7d67078d4888eb5956d3a2d6