code-audit-scripts

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill is coherent with its stated purpose: it runs local code-quality and security scans and outputs a structured JSON report. There are no evident data exfiltration, credential handling, or external dependencies described. The primary concerns are potential command-injection vectors if user-supplied inputs influence shell commands within the underlying scripts, and ensuring the produced report does not inadvertently reveal sensitive information. Overall risk is low to moderate with proper safeguards around input handling and access control.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 03:57 AM
Package URL
pkg:socket/skills-sh/b-open-io%2Fprompts%2Fcode-audit-scripts%2F@20aba6f97be3c98aa8824b56276231c11349ff25