scorecard

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose is legitimate, but the skill routes users to a third-party X-CMD wrapper instead of the official OpenSSF Scorecard tooling. The main risk is supply-chain and transitive trust from remote-script installation and mediated API access, not confirmed malicious behavior.

Confidence: 90%Severity: 64%
Audit Metadata
Analyzed At
Apr 10, 2026, 05:43 AM
Package URL
pkg:socket/skills-sh/x-cmd%2Fskill%2Fscorecard%2F@b15610971addbcfd33b15d09545bf733e86b8e0f