upgrade-dep
Warn
Audited by Socket on Mar 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s purpose is coherent, but its primary mechanism is risky. It directs the agent to fetch and execute an unpinned third-party npm CLI (`yarn-update-dependency@latest`) whose provenance does not match Sentry or Yarn, creating a significant supply-chain and transitive trust risk despite otherwise normal dependency-management behavior.
Confidence: 90%Severity: 78%
Audit Metadata