fjo

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose is coherent, but the skill depends on a non-official X-CMD wrapper and forwards Forgejo tokens into that third-party runtime. There is no direct evidence of malware or exfiltration, yet install trust and credential-handling are weaker than an official Forgejo integration and are not clearly disclosed in the skill.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
Apr 10, 2026, 05:41 AM
Package URL
pkg:socket/skills-sh/x-cmd%2Fskill%2Ffjo%2F@c8129081bbcda6d62061be824c62f28a71c90541