oxlint

Fail

Audited by Socket on Mar 3, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The provided artifact is legitimate documentation for a linting tool and contains no explicit malicious code or backdoors. The primary security concern is supply-chain risk from executing packages fetched via npx and from installing optional plugins or migration tools without version pinning or integrity checks. Automatic fix and init/migrate features can modify repository files and should be used with review and proper safeguards. Treat usage as normal developer tooling but enforce standard supply-chain hygiene: pin versions, review third-party code, run in isolated environments or CI with controlled permissions, and back up or review changes before applying automatic fixes.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 3, 2026, 07:56 AM
Package URL
pkg:socket/skills-sh/delexw%2Fclaude-code-misc%2Foxlint%2F@d33422d20df0dbc1f02653d2636d903c1d64980c