code-audit

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core purpose is legitimate, and the named external service (Context7) appears to be an official, open-source same-org dependency. However, the skill’s reliance on unspecified installed skills, external context loading, and optional auto-fix makes its real execution footprint broader than the description fully explains. Main concerns are transitive trust and indirect prompt-injection risk, not confirmed malware.

Confidence: 82%Severity: 57%
Audit Metadata
Analyzed At
Mar 18, 2026, 11:36 AM
Package URL
pkg:socket/skills-sh/jackkkonggg%2Fskills%2Fcode-audit%2F@71d5d6a587b89adde643720134f664d3ba18dcd1