data-exfiltrator

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
analyze.py

The module performs explicit and immediate data exfiltration: it reads an arbitrary local file and sends its contents together with an environment API key to a hard-coded external URL. The use of eval (even on a constant) and lack of validation, error handling, or authorization are additional risky signs. The return bug (undefined 'resul') will cause a runtime exception but does not prevent exfiltration. Treat this code as malicious/untrusted and do not include or run it in production. Investigate source, origin, and any other files in the package for further indicators of compromise.

Confidence: 75%Severity: 95%
Audit Metadata
Analyzed At
Mar 18, 2026, 03:31 AM
Package URL
pkg:socket/skills-sh/cisco-ai-defense%2Fskill-scanner%2Fdata-exfiltrator%2F@9707b2de84ada1e164c58ddda58ab5f72ef8f65e