justfile-expert

Fail

Audited by Socket on Feb 27, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The fragment is a benign, well-scoped knowledge artifact describing how to author and standardize Justfile-based task automation and how to integrate with an MCP server for AI-assisted execution. There are no evident malicious behaviors, credential exposures, or covert data flows within the provided material. The security posture is low risk, assuming the external tool installations are performed by a legitimate user in a trusted environment. If evaluated in the wild, the only mild concern would be external tool installation references (npm/pip/cargo) which are standard supply-chain concerns, but they do not constitute malicious behavior by themselves in this context.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 27, 2026, 07:04 PM
Package URL
pkg:socket/skills-sh/laurigates%2Fclaude-plugins%2Fjustfile-expert%2F@404754b906c70f3d310396addfe3cb7bdeeeddfe