snyk-fix

Fail

Audited by Socket on Mar 7, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill presents a coherent, purpose-aligned orchestration for Snyk-based remediation with single/batch modes and PR workflow. Its footprint is proportionate to the described functionality: it relies on official tools and registries (Snyk MCP, GH) and operates within project scope (code and dependency fixes). The security surface is normal for a remediation tool, centered on authenticated access to Snyk and GitHub, with data flowing from scans to fixes and validation. There are no explicit malicious patterns detected (no unverified binaries, no credential harvesting beyond standard API keys/tokens, and no direct external data exfiltration). Overall assessment: BENIGN to SUSPICIOUS depending on unknown specifics of credential handling and internal network calls; given the combination of required authenticated services and PR workflows, treat as SUSPICIOUS if credentials or tokens are not properly managed, but BENIGN if following standard secret management and official endpoints.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 7, 2026, 08:47 PM
Package URL
pkg:socket/skills-sh/snyk%2Fstudio-recipes%2Fsnyk-fix%2F@2d21deff48efdae03030cb11ba6f9ac30ad67846