clojure-symbols

Warn

Audited by Socket on Feb 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is functionally coherent and its capabilities align with the stated purpose of finding and editing Clojure symbols using clj-kondo and nREPL introspection. The primary security concerns are: (1) the documentation suggests a download-and-execute installer flow (curl from raw.githubusercontent.com then run) which is a supply-chain risk if executed without verification; and (2) use of nREPL requires connecting to and executing code on JVM processes, which is powerful and can lead to remote code execution if the connected nREPL is untrusted. There are no other signs of malicious behavior, credential harvesting, or exfiltration. Recommend avoiding blind execution of the install script (verify checksums or install from package manager) and only connecting to trusted nREPL endpoints. Overall risk is low-to-moderate due to these operational cautions.

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Feb 28, 2026, 11:38 AM
Package URL
pkg:socket/skills-sh/brettatoms%2Fagent-skills%2Fclojure-symbols%2F@d2a2efc00ea933311a24f71778d24b62fcd7e5fd