typescript-expert

Fail

Audited by Socket on Feb 21, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Destructive bash command detected (rm -rf, chmod 777) BENIGN: The skill fragment is a coherent, legitimate TypeScript expert workflow specification. It outlines analysis, validation, and migration guidance, with no observed malicious data flows or credential access. It does not install or execute untrusted payloads within the fragment itself; any risk depends on how a user executes the included commands in their environment. LLM verification: This skill is functionally coherent and matches its stated purpose (TypeScript expert). It does not contain embedded malware or obfuscated payloads. However, it encourages execution of developer tooling via npx/npm and includes destructive shell examples (rm -rf). Those patterns create supply-chain and accidental-destruction risk: npx can fetch and execute remote packages and rm -rf can delete files if copy-pasted. Overall the artifact is not malicious but poses a moderate supply-chain / operati

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 21, 2026, 04:27 PM
Package URL
pkg:socket/skills-sh/violabg%2Fdev-recruit%2Ftypescript-expert%2F@d86635f315a33ada966d864947c1e8c3f0a7c0a8