dig

Warn

Audited by Socket on Mar 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's behavior is broadly aligned with its stated purpose, but it introduces moderate risk by cloning and analyzing untrusted third-party repositories without pinning or strong provenance checks. No credential harvesting or clearly malicious data exfiltration is present, so this is not malware, but the combination of mutable repo trust and indirect prompt-injection exposure makes it medium risk.

Confidence: 88%Severity: 56%
Audit Metadata
Analyzed At
Mar 30, 2026, 01:22 AM
Package URL
pkg:socket/skills-sh/udecode%2Fbetter-convex%2Fdig%2F@5f606535fdacd3a3c16b7a9f7b7ce306b67412b3