upgrade-dep

Warn

Audited by Socket on Mar 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose is coherent, but its primary mechanism is risky. It directs the agent to fetch and execute an unpinned third-party npm CLI (`yarn-update-dependency@latest`) whose provenance does not match Sentry or Yarn, creating a significant supply-chain and transitive trust risk despite otherwise normal dependency-management behavior.

Confidence: 90%Severity: 78%
Audit Metadata
Analyzed At
Mar 20, 2026, 04:59 PM
Package URL
pkg:socket/skills-sh/getsentry%2Fsentry-javascript%2Fupgrade-dep%2F@c43b730d53a61dda0dc3c433275483e6937dc75e