cve-validation

Fail

Audited by Socket on Mar 3, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

No explicit malicious code was found in the provided skill documentation. The primary risks are operational/supply-chain: dependence on high-value environment credentials, opaque MCP-managed tooling/endpoints, and transitive trust in downstream skills. These create a moderate security risk if MCP tooling or configuration is compromised because credentials and system-context data could be exposed or misused. Recommend applying least-privilege tokens, endpoint/code audits for MCP tools, restricting downstream skill execution to vetted components, and protecting local docs used for consultation to reduce indirect injection risk.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 3, 2026, 08:10 PM
Package URL
pkg:socket/skills-sh/dmartinol%2Fai5-marketplaces%2Fcve-validation%2F@19add3cdc50fb8b67ca5cfe17b7e2968066dcd0a