ashby

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The task scope fits recruiting operations, but the core dependency is an unverified `ashby` CLI that receives Ashby API credentials and candidate data without documented same-org provenance in the provided evidence. That makes the skill high risk even though its stated purpose is coherent.

Confidence: 86%Severity: 82%
Audit Metadata
Analyzed At
Mar 15, 2026, 12:42 AM
Package URL
pkg:socket/skills-sh/danielgwilson%2Fashby-cli%2Fashby%2F@4d5d22b7823be712ebd70d7149cb50f0fb0dad35