scanning-for-vulnerabilities

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The stated purpose is coherent with reading code and dependency files, but the skill gives an AI agent high-risk security scanning capability plus unrestricted shell execution. No clear malicious exfiltration is shown, and plugin provenance appears same-publisher rather than clearly deceptive, so this is better classified as a high-risk vulnerable skill than confirmed malware.

Confidence: 87%Severity: 78%
Audit Metadata
Analyzed At
Apr 2, 2026, 07:57 PM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus-skills%2Fscanning-for-vulnerabilities%2F@d3040ae4ca439425c0b8ff1afd2ed7405d31c3e2