codemap

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core code-search purpose is plausible, but the skill goes beyond that by silently modifying Claude permission settings and broadening persistent Bash access. The npm install path is less concerning than raw-script installers, yet package provenance for `@ulpi/codemap` was not independently verified here. Main risk is stealthy permission escalation, not confirmed malware.

Confidence: 85%Severity: 69%
Audit Metadata
Analyzed At
Mar 15, 2026, 01:31 PM
Package URL
pkg:socket/skills-sh/ulpi-io%2Fskills%2Fcodemap%2F@aae9d168169a454bf012b7a68a2da1312c7535c8