sf-apex

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core Apex generation/review behavior is coherent and mostly benign, but the skill expands trust by instructing transitive installation of additional third-party skills from Jaganpro/sf-skills and references deployment through another skill. No clear credential harvesting, exfiltration, or malware behavior is present, yet the transitive install path and partially unverifiable package provenance make the overall skill medium risk rather than benign.

Confidence: 83%Severity: 56%
Audit Metadata
Analyzed At
Mar 13, 2026, 03:09 PM
Package URL
pkg:socket/skills-sh/Jaganpro%2Fsf-skills%2Fsf-apex%2F@97dbd988e8d22927710b9a5ed786099ca5de2082