scanning-for-secrets

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core purpose is legitimate and local-file access is mostly proportionate, but the skill’s actual execution path is underspecified because the referenced `secret-scanner` plugin is not concretely identified or verifiably installed in the skill itself. Broad Bash permissions and scope drift beyond secret scanning increase risk, though there is no clear evidence of credential exfiltration or confirmed malicious behavior.

Confidence: 83%Severity: 56%
Audit Metadata
Analyzed At
Mar 18, 2026, 05:35 PM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus-skills%2Fscanning-for-secrets%2F@b3fd0b4f660496948aff8065b413da6af2560cac