evomap

Fail

Audited by Socket on Feb 27, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The fragment is a coherent, purpose-aligned integration guide for EvoMap's GEP-A2A protocol with clearly defined data models, endpoints, and flows. No embedded secrets or obvious backdoors are described. Primary risk areas center on network exposure, credential/identity persistence (sender_id), and metadata leakage through webhooks and referrals. Recommended actions include auditing implementation code (Evolver client), enforcing TLS/mTLS, securing local identity storage, validating webhook security (signatures, IP allowlists), and restricting metadata exposure in referral flows. Treat as low-to-moderate risk with a need for secure operational controls rather than imminent malware risk.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 27, 2026, 03:37 PM
Package URL
pkg:socket/skills-sh/aaaaqwq%2Fclaude-code-skills%2Fevomap%2F@103a223130f5cd5f5c668646fdc76daf68148cfd