juicebox-core-workflow-a

Warn

Audited by Socket on Mar 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and core behavior are coherent with a recruiting/search workflow, and there is no clear exfiltration or malicious payload. However, the required 'Juicebox SDK' is not concretely identified or verifiably sourced, the docs links are inconsistent with current official hosting, and the granted npm/pip execution scope is broader than the task needs. This is best classified as medium risk due to trust and provenance ambiguity, not confirmed malware.

Confidence: 83%Severity: 52%
Audit Metadata
Analyzed At
Mar 24, 2026, 04:23 PM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus-skills%2Fjuicebox-core-workflow-a%2F@7211882e96611c06b1c8320e5fb3d4ce196055be