analyze

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill presents a coherent and proportionate tool for initial codebase analysis and reporting. Its footprint—read-only analysis of repository structure, detection of tech stack, and generation of analysis-report.md—fits the stated purpose without introducing credential handling, external data exfiltration, or dangerous automation. Minor concerns relate to reliance on local plugin paths and potential batch-session automation, but these are standard for developer tooling and do not constitute security risks in themselves. Overall, the skill is BENIGN with low risk and clear alignment between stated purpose and capabilities.

Confidence: 98%Severity: 55%
Audit Metadata
Analyzed At
Mar 10, 2026, 06:52 AM
Package URL
pkg:socket/skills-sh/jschulte%2Fstackshift%2Fanalyze%2F@939c3ea69a58da89fa34436dc8761196add7e81b