qodo-get-relevant-rules

Fail

Audited by Socket on Mar 11, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's footprint aligns with its stated purpose: it performs repository checks, reads credentials from trusted sources, constructs structured queries, queries the Qodo API, and presents ranked rules for code generation constraints. There are no evident supply-chain or credential-harvesting patterns, and data flows stay within legitimate boundaries (local config or env vars to a defined API endpoint). Minor concerns include ensuring API keys are not logged and that the Python UUID command is available in the execution environment. Overall, the risk is low to moderate and proportionate to the described task.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 11, 2026, 06:31 PM
Package URL
pkg:socket/skills-sh/qodo-ai%2Fqodo-skills%2Fqodo-get-relevant-rules%2F@5244743a26961f9e772a16b46f60a5a093a07b59