mega-code-status

Warn

Audited by Socket on Mar 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The visible behavior mostly matches a status skill, but it delegates core actions to an externally unverified local `mega_code`/`mega-code` codebase via `uv run`, including an auth check with undisclosed network endpoints. No explicit credential theft or exfiltration is shown, so this is not malicious, but execution trust is only partially established.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Mar 20, 2026, 02:31 AM
Package URL
pkg:socket/skills-sh/wisdomgraph%2Fmega-code%2Fmega-code-status%2F@93a9a64e9a2dcca5c27bae831fa33817e958f8a9