google-styleguides-skills
Warn
Audited by Socket on Feb 23, 2026
1 alert found:
AnomalyAnomalyshell/SKILL.md
LOWAnomalyLOW
shell/SKILL.md
Benign documentation with a standard install-path reference. The footprint is coherent with its stated purpose as a guide, but the install instruction via npx introduces a download-and-run pattern that warrants caution for users. If strictly evaluating the fragment itself, it is not malicious, but the presence of a direct external-install command should be treated as a potential supply-chain risk when users decide to execute it. Recommend clarifying provenance of the external package and encouraging pinned versions or manual review before execution.
Confidence: 72%Severity: 55%
Audit Metadata