Convert XNO Units

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The stated purpose is benign and narrow, but the skill achieves it by executing an unverified, unpinned external npm package (`xno-skills`) that could not be tied to a verifiable publisher or source repository from the provided evidence. No credential theft or malicious data flow is shown, so this is best classified as supply-chain risk rather than confirmed malware.

Confidence: 89%Severity: 72%
Audit Metadata
Analyzed At
Mar 14, 2026, 08:33 AM
Package URL
pkg:socket/skills-sh/casualsecurityinc%2Fxno-skills%2Fconvert-xno-units%2F@cb49a914f1bb2b6604e05a3cd49e049b17ba4a7e