gsp-scaffold

Warn

Audited by Socket on Apr 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities mostly fit its stated scaffolding purpose, and it does not seek credentials or exfiltrate data. Risk comes from executing mutable npm/npx CLIs and especially from parsing install-manifest content into shell actions, which makes repository content a command source; this is proportionate enough to avoid a malicious verdict but not low-risk.

Confidence: 90%Severity: 52%
Audit Metadata
Analyzed At
Apr 11, 2026, 04:04 AM
Package URL
pkg:socket/skills-sh/jubscodes%2Fget-shit-pretty%2Fgsp-scaffold%2F@57a8fd2344324ed119ca76cf1a3ea6e7aabe9955