interface-scaffold-gen

Fail

Audited by Socket on Mar 11, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill describes a coherent interface scaffold generator workflow for producing interface.yaml manifests across multiple targets and SDKs. There is alignment between purpose and the described capabilities: it generates manifests, supports dry-run previews, and provides per-target defaults and per-concept overrides. The execution model relies on standard, well-known development tooling (TypeScript, npx, TSX, Vitest) from official registries, with no apparent credential handling or external data exfiltration. Network exposure and data flows are internal to manifest generation, and there are no suspicious data sinks or unverifiable binaries evident in the provided material. Overall, the skill appears benign with low to moderate risk, dominated by standard supply-chain considerations for npm-based tooling. If anything, ensure explicit use of lockfiles/checksums and explicit provenance tagging for emitted artifacts to strengthen trust.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 11, 2026, 03:54 PM
Package URL
pkg:socket/skills-sh/Itshalffull%2FConcept-Oriented-Programming-Framework%2Finterface-scaffold-gen%2F@c0af73a35106d9b25aac44c5cf00f0e17fa2122b