dry-consolidation

Warn

Audited by Socket on Feb 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is coherently aligned with its stated purpose: scanning a codebase for duplicated code and extracting shared abstractions. It requires filesystem read/write and the ability to run local build/test tooling, which is reasonable for the task. The main risks are operational: the broad allowed shell command capabilities and edit permissions can be abused to run arbitrary project scripts or make large-scale changes without human review, and running package managers introduces standard supply-chain risks (pulling remote packages). I find no evidence of embedded malicious code, hardcoded credentials, remote downloads in the skill itself, or obfuscation. Recommended mitigations: run in a sandboxed environment, require explicit user confirmation before any non-dry-run edits, limit runtime to a review-and-apply workflow, and avoid scanning paths containing secrets.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 27, 2026, 07:23 PM
Package URL
pkg:socket/skills-sh/laurigates%2Fclaude-plugins%2Fdry-consolidation%2F@50ed8e438c6f978f51c5b5297701799737b9f30c