emrah-skills

Fail

Audited by Socket on Mar 4, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

Report 2 convincingly flags critical supply-chain risk due to download-execute of an external Maestro installer embedded in CI guidance. While the material describes testing/Expo scaffolding, the remote-install pattern is risky and warrants remediation. Recommend removing remote installer steps, pinning verified tooling, and tightening CI security to reduce attack surface; treat the presence of such patterns as high-risk in any security assessment.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 4, 2026, 12:43 PM
Package URL
pkg:socket/skills-sh/emrahyurttutan%2Fskills%2Femrah-skills%2F@b7ad6f18d988455aff2822a876b2ed3e938cf03f