soc-compass

Warn

Audited by Socket on Mar 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is mostly coherent with a SOC investigation assistant: it reads workspace state, asks the user to run SIEM queries, and writes reports/verdicts back. The main concern is data-flow integrity: sensitive investigation data and the API key are sent to a Convex-hosted tenant domain that is not clearly verified in the skill as an official SOC Compass API origin. This is not enough to call it malicious, but it is a meaningful trust and confidentiality risk for security-sensitive workflows.

Confidence: 82%Severity: 58%
Audit Metadata
Analyzed At
Mar 20, 2026, 10:21 AM
Package URL
pkg:socket/skills-sh/Hero988%2Fsoc-compass-skill%2Fsoc-compass%2F@2f907dc123c92de79838bd4cb018c9477a2aeab7