sast-orchestration

Fail

Audited by Socket on Feb 26, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill is documentation and orchestration tooling for legitimate SAST workflows. No code in the provided files demonstrates credential harvesting, hidden command-and-control, remote exfiltration, obfuscated payloads, or backdoors. The primary security concerns are supply-chain hygiene and operational hygiene: some examples show unpinned installer commands and silenced errors which increase risk if an attacker compromises upstream packages or tooling. Overall it is appropriate for its stated purpose but operators should harden installs (pin versions, verify integrity) and ensure CI runners and tool outputs are handled securely.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 26, 2026, 07:59 AM
Package URL
pkg:socket/skills-sh/hardw00t%2Fai-security-arsenal%2Fsast-orchestration%2F@5c8169cd1c74dd585c50316f49a01adcea2c61d4