eval-driven-dev

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and capabilities are largely coherent for eval-driven development, and there is no clear credential harvesting or malicious exfiltration flow. However, the install instructions are internally inconsistent with the available public package evidence, so the required third-party dependency is not cleanly verifiable; that makes this a medium supply-chain risk rather than benign.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Mar 18, 2026, 01:32 AM
Package URL
pkg:socket/skills-sh/github%2Fawesome-copilot%2Feval-driven-dev%2F@459f0408e80c33e2aaa86a3894558516a2411f01