cwe-295-insecure-tls-trust-manager
Fail
Audited by Socket on Mar 6, 2026
1 alert found:
Obfuscated FileObfuscated FileSKILL.md
HIGHObfuscated FileHIGH
SKILL.md
The skill is largely consistent with its stated purpose of addressing CWE-295 insecure TLS/SSL configurations in Java. It presents both insecure patterns and secure remediation approaches, which is appropriate for a remediation guide. There are minor concerns about incidentally exposing insecure code patterns and handling of trust store credentials, but these are contextualized within remediation guidance. Overall, the footprint is benign and proportionate to its remediation objective, with no evident external data exfiltration or unauthorized access patterns.
Confidence: 98%
Audit Metadata