4d-add-dependency

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Instruction directing agent to run/execute external content The fragment is a coherent, benign specification describing how a 4D dependency adder should operate. The described flows and file writes match the stated purpose. The main concerns are minor: a truncation typo ('environment4d.jso') and an incomplete sentence at the end, which could reflect an incomplete spec rather than a security hazard. No credentials, external domains, or dubious install sources are implied by the text. Overall, the content is aligned with its stated purpose, with modest room for improvement in completeness of the behavior description.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 16, 2026, 11:40 AM
Package URL
pkg:socket/skills-sh/e-marchand%2Fskills%2F4d-add-dependency%2F@d67cb1d90e0d976798a0b75ab4508067f36c5601