static-vulnerability-detector

Fail

Audited by Socket on Mar 6, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

Overall, the static vulnerability detector skill is internally consistent with its stated purpose: it describes a static analysis workflow that identifies CWE-based vulnerabilities and outputs structured reports. There are no indications of unnecessary credential access, external data exfiltration, or insecure installation behavior. The risk footprint is appropriate for a static analysis guidance tool. No hidden data flows or network communications are described or implied beyond generating local reports.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 6, 2026, 10:22 PM
Package URL
pkg:socket/skills-sh/ArabelaTso%2FSkills-4-SE%2Fstatic-vulnerability-detector%2F@6dbd5524b30ff949d21d7e458182b656313906c6