slop-refinery-setup

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is mostly coherent with its stated purpose as a TypeScript setup/integration helper, and it does not request credentials or route data to suspicious endpoints. The main concern is the explicit installation of another third-party skill via `npx skills add`, which introduces a transitive trust chain and elevates supply-chain risk. Overall: suspicious rather than malicious.

Confidence: 82%Severity: 58%
Audit Metadata
Analyzed At
Apr 23, 2026, 06:46 PM
Package URL
pkg:socket/skills-sh/HOWMZofficial%2Fslop-refinery%2Fslop-refinery-setup%2F@df12081ab9c63492c3126e903b74323e8503d4ec