neovim

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's footprint is coherent with its stated purpose: it enables legitimate, local automation of a Neovim instance via RPC to inspect state and execute code. The data access is appropriate for editor automation and does not introduce external data flows or credential harvesting. Overall risk is low to moderate (Benign) given proper user context and explicit permission to control the local editor. Monitor for accidental exposure of sensitive editor data when querying buffers or LSP state, but nothing indicates malintent or external data exfiltration.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 09:25 AM
Package URL
pkg:socket/skills-sh/fredrikaverpil%2Fdotfiles%2Fneovim%2F@8552d1fdbd84ee1a2a3dc57f53f76d4a5b0ca554