production-code-audit

Warn

Audited by Socket on Apr 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose broadly matches code-audit and refactoring behavior, and there is no evidence of external exfiltration or credential harvesting. However, the skill grants autonomous repo-wide read/write authority and executes an unreviewed local script whose behavior cannot be verified from the supplied material, creating moderate supply-chain and integrity risk.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Apr 13, 2026, 05:53 PM
Package URL
pkg:socket/skills-sh/dokhacgiakhoa%2Fantigravity-lab%2Fproduction-code-audit%2F@ba004017926412358fbe5eccfc5bb38f5b233f97