milady-development

Warn

Audited by Socket on Apr 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's self-modification purpose matches its capabilities, so it is not obviously deceptive. The main concern is high-impact trust expansion: it can install/sync third-party plugin code, run dependency installation, and restart itself, all with minimal provenance controls and transitive trust into upstream repos and npm packages.

Confidence: 82%Severity: 68%
Audit Metadata
Analyzed At
Apr 8, 2026, 01:23 PM
Package URL
pkg:socket/skills-sh/milady-ai%2Fmilady%2Fmilady-development%2F@5b8fe6f6656ef12c5dc83d7eb4db1ba5ede061d7