pre-ship-review

Warn

Audited by Socket on Apr 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s core review behavior is coherent and mostly benign for a pre-ship QA workflow, but its footprint is broadened by transitive skill orchestration and self-modification instructions. The main concrete security issue is install trust: the documented `pip install pyright` path uses an unofficial third-party wrapper rather than the primary publisher distribution, making the toolchain less trustworthy than the skill implies. No credential harvesting, exfiltration endpoints, or clearly malicious data flows are present.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Apr 4, 2026, 09:55 AM
Package URL
pkg:socket/skills-sh/terrylica%2Fcc-skills%2Fpre-ship-review%2F@8a19c2e50589943cd6dea4465ef25be30f3ff1f1