NYC

find-bugs

Warn

Audited by Socket on Feb 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Backtick command substitution detected No code supplied. Unable to perform a concrete security assessment. Please provide the target files or a diff for analysis. LLM verification: This SKILL.md describes a legitimate and useful capability (in-depth branch security/code review). The requested capabilities (git diff, read changed files, run checks) are aligned with the stated purpose. However, the skill lacks operational safeguards for handling secrets and does not constrain execution context or output destinations. That makes it SUSPICIOUS rather than benign: in a hostile or misconfigured agent environment the skill can be used to harvest and exfiltrate repository secrets

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 16, 2026, 12:55 PM
Package URL
pkg:socket/skills-sh/getsentry%2Fwarden%2Ffind-bugs%2F@511ece7796877f203c57a2c45a9068ee82587c88