Skip to main content

package-search

This skill assesses package security risks before adding dependencies, ensuring safer software development practices.

Install this skill

or
75/100

Security score

The package-search skill was audited on May 13, 2026 and we found 3 security issues across 2 threat categories, including 1 high-severity. Review the findings below before installing.

Categories Tested

Security Issues

medium line 229

Template literal with variable interpolation in command context

SourceSKILL.md
229```bash
medium line 236

Template literal with variable interpolation in command context

SourceSKILL.md
236```bash
high line 160

Access to system keychain/keyring

SourceSKILL.md
1601. If a package being evaluated handles auth/secrets (e.g., `jsonwebtoken`, `bcrypt`, `passport`, `oauth2`, `crypto`, `keyring`), check for open secret scanning alerts:
Scanned on May 13, 2026
View Security Dashboard
Installation guide →