rstack-audit

Warn

Audited by Socket on Apr 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core audit behavior is largely coherent and proportionate for a resolved.sh page health check, with official endpoint usage and limited credential scope. The main concern is the explicit transitive skill installation/update command using an unpinned GitHub-backed Skills CLI path, which adds supply-chain risk but does not by itself indicate malicious intent.

Confidence: 90%Severity: 58%
Audit Metadata
Analyzed At
Apr 16, 2026, 03:21 AM
Package URL
pkg:socket/skills-sh/resolved-sh%2Frstack%2Frstack-audit%2F@7c429e8c5a7dc249aa5d1dcb50c701925827a3d1