react-health-audit

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose is a React health audit, but the skill is not proportionately scoped as a mostly read-only analyzer. It mandates environment setup, broad dependency installation, test execution, and parallel agent execution over untrusted repository content, creating medium-high security risk despite a plausible purpose. No clear evidence of credential theft or overt malware is visible in the provided text, but the hidden referenced markdown files and install-and-execute workflow prevent a benign classification.

Confidence: 84%Severity: 71%
Audit Metadata
Analyzed At
Mar 27, 2026, 03:29 PM
Package URL
pkg:socket/skills-sh/somnio-software%2Fsomnio-ai-tools%2Freact-health-audit%2F@a7d2f93793f6f5d117f088254e73b14dfbf0e0bf