tdd-claude-acpx

Warn

Audited by Socket on Mar 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Suspicious. The workflow is broadly aligned with its stated TDD-plus-review purpose, but it relies on an unspecified external `acpx` tool/service and intentionally sends local code, tests, and diffs outside the repo. Without verifiable provenance and endpoint details for `acpx`, the skill carries meaningful supply-chain and data-exposure risk even though it does not show direct credential theft behavior.

Confidence: 79%Severity: 72%
Audit Metadata
Analyzed At
Mar 30, 2026, 09:14 AM
Package URL
pkg:socket/skills-sh/knowlet%2Fclaude-acpx%2Ftdd-claude-acpx%2F@14f7d9171738e42b7e1522d9929e1e86cd637c47