next-cache-components-adoption

Warn

Audited by Socket on Sep 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core migration/edit/build behavior matches the stated Next.js adoption purpose and uses mostly official same-org sources, so this is not fundamentally incompatible with its claim. The main concern is proportionality and trust expansion: it instructs the agent to install another skill transitively, uses mutable `@latest`/remote install paths, and authorizes installation without user confirmation in some cases. I do not see credential theft, covert exfiltration, or malicious data routing.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Sep 11, 2026, 03:29 AM
Package URL
pkg:socket/skills-sh/vercel%2Fnext.js%2Fnext-cache-components-adoption%2F@00bb30ef1b6cdb3946213fa613d3b5a366c13ea243e91b814b61034a9154c0f4
Security Audit — socket — next-cache-components-adoption