ty-type-checking
Warn
Audited by Socket on Feb 27, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The skill manifest is coherent with its stated purpose of enabling the ty type checker within Astral’s ecosystem. Install pathways reference standard, reputable channels (uv tool, pip, VS Code marketplace). Data flows are normal for a developer-focused tooling manifest and do not indicate credential handling, data exfiltration, or autonomous actions. The security footprint is acceptable when installing from official registries and trusted extensions; no anomalous or malicious behaviors are evident in the fragment itself.
Confidence: 75%Severity: 75%
Audit Metadata