codemod-gen

Warn

Audited by Socket on Mar 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The stated purpose is coherent, but the skill asks users to execute an unverified npm CLI with `npx`, provide an OpenAI API key, and likely send code/context to an unspecified external AI backend. This is not fundamentally incompatible with a codemod generator, but install trust and data-flow transparency are incomplete, so risk is medium rather than benign.

Confidence: 74%Severity: 58%
Audit Metadata
Analyzed At
Mar 17, 2026, 07:06 AM
Package URL
pkg:socket/skills-sh/sundial-org%2Fawesome-openclaw-skills%2Fcodemod-gen%2F@c798a9bdf2b0cc75dfb66e9361c922dce0168f02