update-supported-os

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is largely aligned with its stated repository-maintenance purpose and uses mostly official endpoints, but it relies on an unpinned external CLI from a personal GitHub Packages namespace and instructs clear-text package credential storage. This looks more like medium supply-chain and credential-handling risk than malware or clear exfiltration.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Apr 28, 2026, 10:38 PM
Package URL
pkg:socket/skills-sh/dotnet%2Fcore%2Fupdate-supported-os%2F@409823e51ac6da0d11f21ed1c686a8c15d40edda