oxfmt

Fail

Audited by Socket on Mar 3, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

Overall, the provided fragment is a benign, self-consistent description/documentation for the oxfmt tool and its integration into projects. There are no suspicious network calls, credential harvesting, or hidden actions described. The primary security considerations are standard supply-chain risks associated with adding a devDependency from a public registry (npm/pnpm/yarn) and ensuring integrity of the package via lockfiles and trusted registries. Given the lack of executable code or hidden flows, the content aligns with its stated purpose as a formatter integration guide rather than a malicious or dangerous artifact.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 3, 2026, 09:29 PM
Package URL
pkg:socket/skills-sh/delexw%2Fclaude-code-misc%2Foxfmt%2F@4599b9eba157faf95820ae41f3e1a70efbe81a46