aider
Warn
Audited by Socket on Apr 10, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The main issue is install/execution trust: a skill presented as Aider directs users to `x aider`, a third-party X-CMD wrapper, not Aider-AI's official documented installer. That mismatch is disproportionate to the stated purpose and creates transitive supply-chain risk, though there is no direct evidence of credential theft or overtly malicious behavior in the skill text.
Confidence: 87%Severity: 74%
Audit Metadata