5-5-3-2

Warn

Audited by Socket on Apr 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The nutrition-analysis purpose is benign and the visible instructions do not request sensitive credentials or suspicious data exfiltration. However, the mandatory auto-update step and implied skill/CLI update chain are disproportionate to the task and introduce avoidable supply-chain risk. Overall this is better classified as suspicious rather than malicious.

Confidence: 80%Severity: 62%
Audit Metadata
Analyzed At
Apr 24, 2026, 12:30 PM
Package URL
pkg:socket/skills-sh/BogdanovychA%2Fskills%2F5-5-3-2%2F@68fbdf63d905c836cdd465a9594513b3a40180d5