SkillScan
Source
Know what you're installing.
try:
npm package
OpenVSX extension
Token exfiltration
Hostile skill
Scan
⌘ + Enter
29 checks. 13 malicious fixtures. 300-file false-positive corpus.
fixture corpus