engineering-mentor

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The Engineering Mentor skill presents a cohesive, local, non-networked overlay that augments software-forge with teaching gates while keeping all data flows confined to the developer's machine. Its footprint—local profile/ledger storage, checkpointing, and wrapper orchestration—aligns with its stated purpose of guided learning during software builds. There are no obvious credential or remote-exfiltration risks, and no unverifiable binaries or external installations are described. Overall, the risk profile is benign to low, with no urgent security concerns based on the provided documentation.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 10:33 PM
Package URL
pkg:socket/skills-sh/ahmedhamadto%2Fsoftware-forge%2Fengineering-mentor%2F@88090103cc85bda0951e764d76dbb084f700cfe1