dependency-upgrade

Warn

Audited by Socket on Apr 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and capabilities mostly align with dependency upgrade work, and there is no obvious credential theft or exfiltration. However, it encourages unpinned execution of third-party CLIs and includes at least one likely incorrect or weakly verified external tool example, raising medium supply-chain risk.

Confidence: 87%Severity: 52%
Audit Metadata
Analyzed At
Apr 14, 2026, 06:54 PM
Package URL
pkg:socket/skills-sh/sickn33%2Fantigravity-awesome-skills%2Fdependency-upgrade%2F@4e99a64e4b4a4d695f13d9a3c5b1ea10f459d8bf