skill-security-auditor

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The Skill Security Auditor is coherently aligned with its stated purpose of pre-install security gating and vulnerability scanning. Its workflow relies on static analysis of provided skill code and documentation, without executing external binaries or exfiltrating data. There are no evident mismatches between claimed capabilities and described behavior; no unverifiable binaries or credential forwarding are described. Overall, the tool appears benign with respect to the four evaluation dimensions, though real-world deployment should ensure dependency databases are trustworthy and that SKILL.md prompts are thoroughly checked for injection patterns. PASS with remediation guidance as needed when vulnerabilities or risky patterns are detected.

Confidence: 98%Severity: 55%
Audit Metadata
Analyzed At
Mar 10, 2026, 11:43 PM
Package URL
pkg:socket/skills-sh/alirezarezvani%2Fclaude-skills%2Fskill-security-auditor%2F@6a138d7f3a8a6d2d898753ce34d5e1e72be99711