Sherpa

Pass

Audited by Socket on Mar 10, 2026

Checks
Malicious behaviorInjection, exfiltration, untrusted installs
Security concernsCredential exposure, tool/trust exploitation
Code obfuscationHidden or obfuscated code
Suspicious patternsReconnaissance, excessive autonomy, resource use
Audit Metadata
Analyzed At
Mar 10, 2026, 07:31 PM
Package URL
pkg:socket/skills-sh/simota%2Fagent-skills%2Fsherpa%2F@c8e1587a6c8d24fa77d4c7ad5a3fa2901ef55c9e