procedural-fish-render

Warn

Audited by Socket on Apr 6, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated capability matches the skill’s purpose, but its core behavior is to fetch and run project code from a fixed repository that is currently not publicly reachable or verifiable, using a mutable branch. That makes the install/execution trust disproportionately weak for a rendering helper even without direct evidence of credential theft.

Confidence: 88%Severity: 82%
Audit Metadata
Analyzed At
Apr 6, 2026, 10:05 AM
Package URL
pkg:socket/skills-sh/vibe-motion%2Fskills%2Fprocedural-fish-render%2F@0d0a6d44300300d92cbb9ccbb0c0f6d00c00fd9c