exa-security-basics

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill presents a coherent and proportionate approach to Exa secret management and access control. It aligns with the stated purpose by outlining environment-based secret handling, secret rotation, least-privilege patterns, and audit logging. While data flows include legitimate external API calls and audit endpoints, there is a non-zero risk of secret exposure if logs or dashboards capture raw keys; mitigations should be explicit (e.g., masking, avoiding log of secrets, use of short-lived tokens, and secure log handling). No unverifiable binaries or external supply-chain risks are evident. Overall, the footprint is Benign with moderate security risk due to credential exposure potential, and it remains within expected boundaries for a security-best-practices guide.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 05:48 PM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus-skills%2Fexa-security-basics%2F@df69b6ac3c8afa559101200504a4db95a409f988