fix-imports

Warn

Audited by Socket on Feb 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Backtick command substitution detected This 'fix-imports' skill is coherent with its stated purpose: it scans for broken imports, caches resolution patterns, creates a plan, and applies fixes using shell tools and an editor, with verification steps. It does not contain overtly malicious code or remote exfiltration. The main security concerns are operational: aggressive global text replacements (sed) and automatic commits can cause unwanted or incorrect changes; persistent/shared caches may carry stale or cross-project mappings; and the skill assumes broad local tool permissions. These are safety/usability risks rather than evidence of malware. LLM verification: The skill is a legitimate refactoring utility that automates detection and repair of broken imports with session persistence and resume capability. It does not exhibit direct malware behavior (no exfiltration, no embedded credentials, no external command-and-control). The primary security concerns are operational: automated in-place edits (sed/Edit) combined with automatic commits and a shared persistent cache increase the blast radius and allow poisoning if an attacker can tamper with cache/sta

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Feb 21, 2026, 12:27 PM
Package URL
pkg:socket/skills-sh/manastalukdar%2Fclaude-devstudio%2Ffix-imports%2F@245bee9a61c8d3d2b2f6d0066c164ef8d380a8fd