diffity-resolve

Warn

Audited by Socket on Mar 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The workflow mostly matches the stated purpose of resolving review comments, but the key risk is install trust: it depends on an unpinned third-party `diffity` npm CLI whose official provenance and documentation could not be publicly verified. The skill also lets the agent act on untrusted review content and perform autonomous thread updates, raising medium overall risk even without clear evidence of credential theft or overtly malicious behavior.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
Mar 25, 2026, 04:18 AM
Package URL
pkg:socket/skills-sh/kamranahmedse%2Fdiffity%2Fdiffity-resolve%2F@bca11746cc2bb008a598194eef85cbe9dcbe844d