Most security tools ask whether a dependency is already notorious. Socket asks a ruder, more useful question: what will this code do after you invite it inside?