deliverable-upgrade

Warn

Audited by Socket on Apr 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill’s capabilities mostly match its stated purpose: it upgrades the 'deliverable' skill and shows changes. The main risk is supply-chain and transitive trust: it pulls mutable remote content from GitHub and can invoke 'npx skills add' to install/update skill code without pinning or verification. That is suspicious but not malicious; there is no credential harvesting, hidden exfiltration, or unrelated access.

Confidence: 91%Severity: 73%
Audit Metadata
Analyzed At
Apr 16, 2026, 08:59 AM
Package URL
pkg:socket/skills-sh/canhta%2Fdeliverable%2Fdeliverable-upgrade%2F@efedb5dadf19be0aae50c8962a4c855ee5ef9765