explain-code

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core purpose is benign, but the skill expands scope by requiring a separate skill, fetching broad untrusted web content, and using ambiguous/unpinned Playwright CLI execution. No direct credential harvesting or malicious exfiltration is present, but supply-chain and prompt-injection exposure are material.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Apr 9, 2026, 08:36 PM
Package URL
pkg:socket/skills-sh/flora131%2Fatomic%2Fexplain-code%2F@bfc4bd01e597afe1a9d2394c4a21472050aeb8e7