True, but as mentioned in the thread, this is how it works. That also makes it super fast and it only needs to analyze the manifest for your build instead of scanning or uploading all your code.
Socket is designed to work without the need to analyze, upload, or share your source code. The only data we collect from your repository are the manifest files (package.json, package-lock.json, yarn.lock, etc.).
We use the dependency snapshot to determine the list of packages used by your repository, perform our open source risk analysis, and produce a report.
More info here: https://docs.socket.dev/docs/faq