Private Network Security Scan

Fail

Audited by Socket on Feb 28, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill is a coherent, legitimate private network scanning workflow: capabilities align with its stated purpose, and the described tools and checks are appropriate. The primary security concerns are operational: (1) the workflow runs a local scan script with sudo — that script must be audited to ensure it is not malicious; (2) active network scanning and DNS AXFR attempts generate traffic that may be disruptive or unauthorized in some environments; (3) temporary files may contain sensitive metadata if not cleaned up on failure. There is no evidence of external data exfiltration, obfuscated payloads, or instructions to fetch and execute remote binaries. Recommended mitigations: verify and audit the scan_private_network script and any nmap scripts used, run scans only with explicit authorization, avoid running as root unless necessary, and securely handle or encrypt scan artifacts.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 28, 2026, 12:52 PM
Package URL
pkg:socket/skills-sh/bizshuk%2Fllm_plugin%2Fprivate-network-security-scan%2F@b9507570c6b999a340ea712558acc4286c58d3ab