ecosystem-security

Warn

Audited by Socket on Apr 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s stated purpose is coherent as a security orchestrator, but its actual footprint is under-specified and depends on two undefined sub-skills that are automatically invoked. There is no direct evidence of malware, credential theft, or hostile exfiltration in the provided text, yet the transitive-trust model, always-on message inspection, and missing install/data-flow details make it medium risk rather than benign.

Confidence: 82%Severity: 61%
Audit Metadata
Analyzed At
Apr 18, 2026, 08:59 PM
Package URL
pkg:socket/skills-sh/fatih-developer%2Ffth-skills%2Fecosystem-security%2F@9d49666bb499fefe8b9597337348c86873640817