fix-linting-types-on-pr

Warn

Audited by Socket on Mar 24, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose is coherent, and the named tools are official, but the skill is high-risk because it checks out attacker-controlled PR code (including forks), runs project install/build commands on that code, edits files, and pushes results back using the user's credentials. The main issue is unsafe execution of untrusted PR content plus write-back capability, not overt malware or credential harvesting.

Confidence: 92%Severity: 76%
Audit Metadata
Analyzed At
Mar 24, 2026, 04:11 PM
Package URL
pkg:socket/skills-sh/storybookjs%2Fstorybook%2Ffix-linting-types-on-pr%2F@f9f43a17af26b588d3567b2d909586ec0dc45f02