zeabur-template
Warn
Audited by Socket on Apr 6, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS due to scope creep rather than clear malware: the skill claims to avoid deployment use, yet instructs the agent to deploy, publish, exec into services, restart services, and delete projects. Install/source trust is moderate because it uses npm `npx` for an apparently official CLI, but the unpinned `@latest` package and operational breadth raise meaningful risk.
Confidence: 82%Severity: 58%
Audit Metadata