polish

Warn

Audited by Socket on Mar 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The polish skill itself is benign in scope and does not request credentials or route data off-host, but it introduces unnecessary transitive trust by requiring another skill from an apparently unrelated publisher via a mutable GitHub reference. Main concern is supply-chain exposure, not malicious behavior in the provided skill text.

Confidence: 90%Severity: 56%
Audit Metadata
Analyzed At
Mar 16, 2026, 06:08 PM
Package URL
pkg:socket/skills-sh/kazdenc%2Fbuilder-skills%2Fpolish%2F@206bcb2cd9955df96880ed81803eba733a471c8e