dependency-scanning

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Installation of third-party script detected All findings: [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [CRITICAL] command_injection: URL pointing to executable file detected (CI010) [AITech 9.1.4] [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [CRITICAL] command_injection: Pipe-to-shell or eval pattern detected (CI013) [AITech 9.1.4] [CRITICAL] command_injection: URL pointing to executable file detected (CI010) [AITech 9.1.4] [HIGH] command_injection: Reference to external script with install/setup context (SC005) This skill is coherent with its stated purpose (dependency scanning / SCA). I found no evidence of covert malicious behavior in the provided document. The main security concerns are best-practice risks: use of a floating GitHub Action ref (master), examples that download and execute remote installers without checksum verification (wget/curl | sh), and broad suppression examples that could mask vulnerabilities if copied without care. These are operational/security hygiene issues rather than indicators of malware. Overall the document is useful but should be hardened before copy/paste into production CI.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 16, 2026, 01:38 PM
Package URL
pkg:socket/skills-sh/bagelhole%2Fdevops-security-agent-skills%2Fdependency-scanning%2F@af83f6f12be751b996ec1191c4494882041ef294