scanning-api-security

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's actual footprint does not cleanly match its stated purpose. It claims API security scanning but mainly instructs the agent to scaffold and implement APIs, while granting Bash execution under a security-themed namespace without clear scanning boundaries or verified tool provenance. No direct credential theft or exfiltration is evident, so this is not confirmed malware, but it is a medium-risk, poorly aligned skill.

Confidence: 81%Severity: 54%
Audit Metadata
Analyzed At
Mar 13, 2026, 11:19 AM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus-skills%2Fscanning-api-security%2F@b5b565296965838bc1414e9d0e52dd5c84b0b3ac