react-health-audit
Warn
Audited by Socket on Mar 27, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated purpose is a React health audit, but the skill is not proportionately scoped as a mostly read-only analyzer. It mandates environment setup, broad dependency installation, test execution, and parallel agent execution over untrusted repository content, creating medium-high security risk despite a plausible purpose. No clear evidence of credential theft or overt malware is visible in the provided text, but the hidden referenced markdown files and install-and-execute workflow prevent a benign classification.
Confidence: 84%Severity: 71%
Audit Metadata