cwe-295-insecure-tls-trust-manager

Fail

Audited by Socket on Mar 6, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill is largely consistent with its stated purpose of addressing CWE-295 insecure TLS/SSL configurations in Java. It presents both insecure patterns and secure remediation approaches, which is appropriate for a remediation guide. There are minor concerns about incidentally exposing insecure code patterns and handling of trust store credentials, but these are contextualized within remediation guidance. Overall, the footprint is benign and proportionate to its remediation objective, with no evident external data exfiltration or unauthorized access patterns.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 6, 2026, 09:39 PM
Package URL
pkg:socket/skills-sh/DevelopersCoffee%2Fjava-cwe-security-skills%2Fcwe-295-insecure-tls-trust-manager%2F@da981a0a4f7f501da21bae2d368cd23ce48ad675