make-it-pretty

Fail

Audited by Socket on Feb 21, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

Functionally benign for its stated purpose (automated formatting and light refactoring) but carries moderate supply-chain and execution risk: unpinned runtime installs via npx, shell-based execution that modifies repository state (git stash), and fallback behaviors that expand file-scope. No direct signs of credential theft, network exfiltration, obfuscation, or embedded backdoors in the provided fragment. Recommend hardening: require explicit confirmations, pin formatter versions or use preinstalled binaries, default to dry-run/check modes, and restrict scope to explicit files.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 21, 2026, 12:26 PM
Package URL
pkg:socket/skills-sh/manastalukdar%2Fclaude-devstudio%2Fmake-it-pretty%2F@80e13f31425426688466426106718da40acb25a3