performance

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is mostly benign performance documentation, but it includes unnecessary transitive instructions to install another skill from an external GitHub repo via an `npx`-based workflow. No direct credential theft or exfiltration is shown, so this is not malicious; the main issue is supply-chain and inherited-permissions risk disproportionate to a reference guide.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
Mar 13, 2026, 02:14 PM
Package URL
pkg:socket/skills-sh/krzysztofsurdy%2Fcode-virtuoso%2Fperformance%2F@fd816dd2eec9a0482208940bd5088aeebc88f347