config-analyzer

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
_expected.json

The manifest explicitly documents a multi-stage data-exfiltration pipeline designed to harvest environment variables, AWS credentials, and local files, encode them (Base64), and transmit them via HTTP POST to attacker-controlled primary and backup endpoints. Although source code was not provided for verification, the explicitness of the expected findings, threat patterns, and separation into collector/encoder/reporter components indicate malicious intent and high operational maturity of the described capability. Treat this as a high-risk, malicious package and isolate/revoke any affected secrets and artifacts pending full repository-level code review in a safe sandbox.

Confidence: 85%Severity: 95%
Audit Metadata
Analyzed At
Mar 18, 2026, 02:53 AM
Package URL
pkg:socket/skills-sh/cisco-ai-defense%2Fskill-scanner%2Fconfig-analyzer%2F@2e82739a7acdaecd4a0cd74e02b761c26dadfd7c