security-scan

Warn

Audited by Socket on May 6, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is coherent and mostly locally scoped, with official install paths and no obvious credential-harvesting or stealth behavior. However, it grants an AI agent broad security-scanning capability against arbitrary codebases, which is high risk by category even though the implementation footprint appears proportionate to its stated purpose.

Confidence: 89%Severity: 72%
Audit Metadata
Analyzed At
May 6, 2026, 08:46 PM
Package URL
pkg:socket/skills-sh/devbyray%2Fagent-skill-security-scan%2Fsecurity-scan%2F@ee8297a05d6be10da3b7d83e10f6896ca4edc5ed