bump-deps

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill's stated purpose (automating dependency bumps using taze, with safe rules for majors and updating Bun catalogs) is coherent and the requested file reads/writes align with that purpose. However, the workflow requires running external tooling (taze, ni) and a local script (scripts/run-taze.sh) without instructing verification, pinning, or review. Those download-and-execute patterns and automatic edits to manifests create a non-trivial supply-chain risk: a compromised taze package or an unreviewed run-taze.sh could execute arbitrary code and modify many files across a monorepo. The skill does incorporate user prompts for major updates, which reduces autonomous destructive changes, but minor/patch updates are applied automatically. Overall this is not confirmed malware, but it is a medium/high supply-chain risk and should be used only when the invoked tooling and local scripts are audited/pinned and the user understands the write operations that will occur.

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 01:34 AM
Package URL
pkg:socket/skills-sh/paulrberg%2Fdot-agents%2Fbump-deps%2F@6fbcac2bc91ffb423e02fc4a70c26271f93537bb