dependency-audit

Fail

Audited by Socket on Mar 7, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The Dependency Audit skill presents a coherent, purpose-aligned tool for evaluating risk across licenses, maintenance, security, and bloat in dependency trees. It relies on standard, defensible data sources (declared dependencies, lock files, known CVE databases) and outputs a prioritized remediation plan. No explicit credential requirements or dangerous data flows are evident in the described workflow. The primary security considerations center on external CVE data access and any optional network calls; ensure explicit user consent and clear data-handling policies for external lookups. Overall, the footprint is benign and proportionate to the stated purpose, with moderate security risk primarily tied to external advisory lookups rather than credential exposure or file-system hoarding.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 7, 2026, 08:40 PM
Package URL
pkg:socket/skills-sh/mathews-tom%2Fpraxis-skills%2Fdependency-audit%2F@6f3885250b988399386e3d765a015259826fd65b