cybercentry-cyber-security-consultant

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's main behavior matches its stated purpose, and the ACP install path appears to be the official same-org source rather than an unrelated payload. However, it asks users to install another toolchain, sends user-supplied security context to an external service, and includes an example that can automatically grant access based on returned advice. The biggest concerns are transitive trust, outbound sharing of potentially sensitive security context, and moderate supply-chain risk from unpinned GitHub+npm setup, not confirmed malware.

Confidence: 88%Severity: 56%
Audit Metadata
Analyzed At
Mar 18, 2026, 04:24 AM
Package URL
pkg:socket/skills-sh/Cybercentry%2Fcybercentry-agent-skills%2Fcybercentry-cyber-security-consultant%2F@7a680f02c5384c372cd72fa971de578b33e91373