juicebox-cost-tuning

Warn

Audited by Socket on Mar 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose is benign, but the visible skill is underspecified and grants broader shell/network capabilities than its cost-optimization role requires. No explicit malicious or credential-stealing behavior is shown, yet the wildcard `curl`/`gh` permissions and third-party authorship make the skill riskier than a normal documentation-style guide.

Confidence: 81%Severity: 61%
Audit Metadata
Analyzed At
Mar 24, 2026, 04:30 PM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus-skills%2Fjuicebox-cost-tuning%2F@471fd88be5992feed206331c266dafe3d2454fff