analyzing-projects

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Installation of third-party script detected Benign. The code fragment serves as a structured guide for project analysis with no suspicious data flows or credential handling. Its footprint is coherent with its stated purpose as an onboarding/analysis skill rather than a runnable malware or credential-stealing utility. LLM verification: BENIGN: The skill content describes a standard project-analysis workflow with reads from project files and generation of a summary report. No harmful behaviors or credential access are evident, and the only suspicious note is a static scanner finding about npm install in documentation, which does not imply actual execution or data exfiltration.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 15, 2026, 08:22 PM
Package URL
pkg:socket/skills-sh/cloudai-x%2Fclaude-workflow-v2%2Fanalyzing-projects%2F@d5ea1593f686346fe3c67b57ce2fbb83f1fc09fa