skill-guard

Warn

Audited by Socket on Apr 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core purpose is coherent for a security-audit skill, and there is no clear credential theft or hidden exfiltration. However, the skill has disproportionate write capabilities for an analyzer: it can commit, push, fork, and open PRs on GitHub, creating autonomous external actions and expanding risk beyond local review. Safe only with strict per-action user approval and no automatic publishing.

Confidence: 88%Severity: 71%
Audit Metadata
Analyzed At
Apr 11, 2026, 06:07 AM
Package URL
pkg:socket/skills-sh/j4rk0r%2Fclaude-skills%2Fskill-guard%2F@96252b9e4e7a5eccb1ce064d75c35265e982cb29