exa-policy-guardrails

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The Exa Policy & Guardrails skill appears coherent with its described purpose: it provides lint rules, pre-commit hooks, CI policy checks, and runtime guardrails to enforce Exa best practices and prevent secret leakage. The footprint is proportionate and relies on standard tooling (ESLint, pre-commit, Open Policy Agent, runtime guards) without evident suspicious data flows or unverifiable binaries. While the code examples use sensitive-key patterns for demonstration, there is no evidence of credential harvesting or exfiltration in the supplied material. Overall, the risk posture is benign with careful consideration of demonstration patterns; the documented patterns align with the intended purpose rather than diverge into dangerous capabilities.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 01:03 AM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus-skills%2Fexa-policy-guardrails%2F@bdbcb11ec213d7a2d49c2744a0e46f376e12e570