personize-code-pipelines

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

This skill is broadly aligned with its stated purpose and mostly uses expected install and API patterns, so it does not look malicious. However, it is medium risk because it enables autonomous external actions, processes untrusted content that can influence those actions, and uses an unpinned Trigger.dev CLI plus a less independently verifiable Personize SDK provenance than ideal.

Confidence: 84%Severity: 66%
Audit Metadata
Analyzed At
Mar 14, 2026, 07:07 AM
Package URL
pkg:socket/skills-sh/personizeai%2Fpersonize-skills%2Fpersonize-code-pipelines%2F@ae229e7cbad14c9aab8f006aa6b6179c8bf16ff1