ship-sails-app

Warn

Audited by Socket on Apr 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s overall purpose is coherent for a Sails/Vara router, but it expands trust through a preamble that executes a local updater binary and through transitive routing into other skills. The main additional concern is install-trust inconsistency: the Rust/Sails guidance aligns with official ecosystem tooling, while the frontend `npx create-vara-app` command does not match official Vara documentation. No credential harvesting, exfiltration, or clearly malicious data flow is present in this fragment, but the updater and transitive-skill pattern keep risk above benign.

Confidence: 88%Severity: 57%
Audit Metadata
Analyzed At
Apr 4, 2026, 12:59 PM
Package URL
pkg:socket/skills-sh/gear-foundation%2Fvara-skills%2Fship-sails-app%2F@bf486b6e5007d30891fca9c98980b5d01d88122b