sherlock

Warn

Audited by Socket on Mar 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

BENIGN with elevated operational risk. The skill's capabilities fit its stated purpose and there is no evidence of credential harvesting, remote exfiltration, or suspicious install paths, but its autonomous loop, Bash access, and reliance on repository-defined test commands create meaningful security risk if used on untrusted codebases.

Confidence: 89%Severity: 66%
Audit Metadata
Analyzed At
Mar 23, 2026, 05:51 PM
Package URL
pkg:socket/skills-sh/Codeminer42%2Fskills%2Fsherlock%2F@79d598cc801a64506304bd610098ae9c3621810f