npm-to-pnpm

Fail

Audited by Socket on Mar 1, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This is a legitimate migration guide for converting npm projects to pnpm. It contains standard and expected instructions (pnpm import, pnpm install, workspace changes, CI updates). The primary security concerns are procedural rather than malicious content: (1) the document instructs users to run remote install scripts via curl|sh and PowerShell iwr|iex — a high-risk distribution pattern even when pointing to an official domain; (2) it expands execution/trust surface by enabling lifecycle scripts and recommending third-party GitHub Actions in CI. There is no direct evidence of obfuscated or malicious code, credential harvesting, or exfiltration instructions within the text. Recommended mitigations: prefer installing pnpm through package manager or review the install script before executing, pin action versions and review their code, avoid enabling pre/post scripts unless necessary, and scope CI secrets carefully. Overall the content appears benign but carries moderate supply-chain execution risk due to download-and-execute instructions and CI action recommendations.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 1, 2026, 06:31 PM
Package URL
pkg:socket/skills-sh/ghosttypes%2Fff-5mp-api-ts%2Fnpm-to-pnpm%2F@2f59c1243a8ced19f718569918cbdc8b3b86137a