diffity-resolve-tree

Warn

Audited by Socket on Mar 25, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s behavior mostly matches its stated code-review purpose, but it depends on a not-clearly-verified external CLI and converts untrusted remote comments into code edits and remote actions. This looks more like a workflow skill with meaningful supply-chain and prompt-injection risk than outright malicious content.

Confidence: 81%Severity: 62%
Audit Metadata
Analyzed At
Mar 25, 2026, 01:04 AM
Package URL
pkg:socket/skills-sh/kamranahmedse%2Fdiffity%2Fdiffity-resolve-tree%2F@bde33fadbd9ec7b724f308ab5a47b389263659dd