cadence

Warn

Audited by Socket on Apr 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core Cadence reference content is benign and aligned with its purpose, but the skill also pushes transitive skill installation and a remote MCP on a Railway domain via unpinned `npx` execution. That footprint is somewhat broader than a documentation/reference skill and creates medium supply-chain and data-exposure risk, though there is no clear credential theft or confirmed malicious behavior.

Confidence: 79%Severity: 56%
Audit Metadata
Analyzed At
Apr 3, 2026, 03:30 PM
Package URL
pkg:socket/skills-sh/outblock%2Fcadence-lang.org%2Fcadence%2F@d8685df2ae527fb59db8e5d640581779c20dfbce