dependency-auditor

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The Dependency Auditor skill presents a coherent, safety-oriented tool that fits its stated purpose of auditing dependencies before installation. Its footprint—read-only manifests, no direct installs, reliance on manual vulnerability references—appears proportionate and low-risk. The main caveat is reliance on external advisories and user interpretation for remediation decisions; explicit integration with official advisories and verifiable checks could strengthen trust. Overall, the skill is BENIGN with MEDIUM risk considerations primarily around human interpretation and the potential for outdated advisories if not periodically updated.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 04:41 PM
Package URL
pkg:socket/skills-sh/useai-pro%2Fopenclaw-skills%2Fdependency-auditor%2F@73ba14c441dbde6e8d0427c6c8cc5929688618ee