java
Warn
Audited by Socket on Mar 1, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
This file is documentation for the Google Java Style Guide and contains code examples and guidance only. There is no embedded executable code, credential requests, or suspicious network endpoints. The single notable security consideration is the install instruction that asks the agent/user to run `npx skills add testdino-hq/google-styleguides-skills/java`, which introduces a transitive skill installation and therefore a supply-chain/trust risk if the referenced skill repository is untrusted or compromised. Overall the document itself appears benign, but follow-up review of the referenced skill/package is recommended before executing the install command.
Confidence: 85%Severity: 65%
Audit Metadata