debugging-code
Warn
Audited by Socket on Mar 10, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
Overall, the skill’s footprint is conceptually aligned with its stated purpose of interactive debugging, but it hinges on a high-risk, unverifiable installation flow (curl|bash) to acquire the dap tool and a background daemon for session management. This creates supply-chain and persistence concerns that elevate risk beyond a benign debugging helper. Treat as SUSPICIOUS with elevated security risk due to unverifiable binary installation and potential long-running background behavior; require verifiable installation methods (official package registries, signed binaries, or containerized tooling) and explicit user consent/approval for daemon usage to move toward Benign.
Confidence: 98%Severity: 75%
Audit Metadata