devex-review

Warn

Audited by Socket on May 5, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core DX-audit behavior is legitimate and install provenance is mostly coherent with official gstack/Bun sources, but the skill’s real footprint is much broader than its stated purpose. Telemetry/brain sync, autonomous config changes, CLAUDE.md injection, and repo commits make it over-scoped for a review skill, creating medium-high risk even without clear malicious intent.

Confidence: 88%Severity: 68%
Audit Metadata
Analyzed At
May 5, 2026, 05:23 AM
Package URL
pkg:socket/skills-sh/garrytan%2Fgstack%2Fdevex-review%2F@5d976f12d6272d5057c3a8fbda81835c4dba16f9