knip

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The fragment is a well-structured, non-malicious instructional guide for using Knip to clean up a codebase. It adheres to a configuration-first philosophy and provides clear steps, safety considerations, and standard commands. The primary security consideration is the conventional supply-chain risk of pulling tooling from npm; this should be mitigated by verifying the package source and registry. Overall, the guidance is sound, with low to moderate risk depending on tool provenance and user review of fixes.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 18, 2026, 04:51 PM
Package URL
pkg:socket/skills-sh/brianlovin%2Fagent-config%2Fknip%2F@3064a4500e57a233b8aab475ddff0f59f1b81fe5