engineering-skills

Warn

Audited by Socket on Apr 12, 2026

3 alerts found:

Anomalyx2Security
AnomalyLOW
self-improving-agent/skills/extract/SKILL.md

SUSPICIOUS. The core behavior is mostly aligned with the stated purpose of turning local patterns into reusable skills, and there is no direct credential harvesting or remote payload execution. However, the skill relies on an unverified delegated agent and references transitive install/publish commands without clear provenance, so the trust boundary extends beyond what is documented.

Confidence: 84%Severity: 52%
AnomalyLOW
senior-security/SKILL.md

SUSPICIOUS: the skill is coherent with its stated security-review purpose, but it equips an AI agent with offensive security and penetration-testing guidance that can be misused against unintended targets. No strong signs of malware, credential harvesting, covert behavior, or suspicious data routing are present in the provided skill text.

Confidence: 87%Severity: 68%
SecurityMEDIUM
red-team/SKILL.md

SUSPICIOUS/HIGH-RISK skill. Its footprint is internally consistent with a red-team planning skill, but the purpose itself gives an AI agent offensive security capability, including credential-access, defense-evasion, and exfiltration planning. No strong supply-chain or credential-harvesting indicators are present in the supplied text, so this is not confirmed malware; it is a high-risk offensive-security skill.

Confidence: 91%Severity: 86%
Audit Metadata
Analyzed At
Apr 12, 2026, 04:38 PM
Package URL
pkg:socket/skills-sh/alirezarezvani%2Fclaude-skills%2Fengineering-skills%2F@48d392a315ca03d42f011a1e4defbef5dcb7c9e2