NYC

sweetviz

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Installation of third-party script detected All findings: [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] BENIGN: The document accurately describes legitimate Sweetviz-based EDA capabilities, with safe install paths, proportional data access, and straightforward data flows limited to local analysis and artifact generation. The best report among the three is Report 2, which provides clear, cohesive guidance and aligns with expected security and data-handling norms.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 16, 2026, 10:53 AM
Package URL
pkg:socket/skills-sh/vamseeachanta%2Fworkspace-hub%2Fsweetviz%2F@c62f21ace0ef555b3eb13466a00b61c4940dcb22