NYC

jules

Fail

Audited by Socket on Feb 19, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Installation of third-party script detected This skill/documentation is internally consistent: capabilities match stated purpose (delegating code work to Jules), and the commands and data flows are plausible for that goal. There is no direct evidence of malware or obfuscation in the provided content. The primary security considerations are supply-chain and data exposure risks inherent to installing and using a third-party CLI that sends repository contents to an external service and can apply and push changes. Treat this as a trust decision: verify the publisher/package, avoid using on sensitive code without approval, and always review changes before applying/pushing. LLM verification: This skill's capabilities are consistent with its stated purpose: it legitimately needs access to git metadata, repo files, and the ability to apply and push changes to implement automated task delegation to the Jules agent. There is no evidence of obfuscation, hardcoded secrets, or malicious code in this SKILL.md text. The primary security concern is expected and inherent: it sends repository context and task prompts to an external service (Google Jules) and can automatically apply and push cod

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 19, 2026, 11:37 AM
Package URL
pkg:socket/skills-sh/sanjay3290%2Fpostgres-skill%2Fjules%2F@b24a69862a4a78c1b0740ba2d6ea1a5bbc07af33