analyzing-projects

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Installation of third-party script detected The code fragment is a benign, self-describing project analysis template. It defines a methodical workflow for analyzing a codebase (tech stack detection, project structure, patterns, and workflow) and provides an output format. There are no read/write of sensitive data, no network activity, and no credential handling observed. The footprint is coherent with the stated purpose of onboarding and architecture assessment. No suspicious behavior detected. LLM verification: BENIGN: The skill content describes a standard project-analysis workflow with reads from project files and generation of a summary report. No harmful behaviors or credential access are evident, and the only suspicious note is a static scanner finding about npm install in documentation, which does not imply actual execution or data exfiltration.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 16, 2026, 04:30 PM
Package URL
pkg:socket/skills-sh/cloudai-x%2Fclaude-workflow%2Fanalyzing-projects%2F@d5ea1593f686346fe3c67b57ce2fbb83f1fc09fa