dx-optimizer

Warn

Audited by Socket on May 5, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The stated purpose and capabilities are coherent for a DX optimization skill, and the text does not request credentials or route data externally. The main concern is install/execution trust: external evidence shows unofficial aggregator-driven distribution, transitive skill installation, and raw GitHub fetches with weak provenance and no visible checksum/signature verification. This is a supply-chain and trust-boundary issue rather than confirmed malicious behavior.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
May 5, 2026, 12:27 AM
Package URL
pkg:socket/skills-sh/saeed-vayghan%2Fgemini-agent-skills%2Fdx-optimizer%2F@d955f169086b462c141440c6873d2419b035f9d8