scanning-for-vulnerabilities

Fail

Audited by Socket on Mar 11, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

Overall, the skill appears benign and coherent with its stated purpose of vulnerability scanning. The footprint is proportionate to the task, with plausible data flows for scanning and reporting. The primary concerns are the lack of explicit provenance for the vulnerability-scanner plugin and explicit handling of scan-related credentials or secrets. Providing clear sources for the plugin and ensuring secure, auditable data handling and optional opt-in data sharing would strengthen trust.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 11, 2026, 11:38 PM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus-skills%2Fscanning-for-vulnerabilities%2F@53dbd78f38c26484b16623642df0bc4ae9e45c2c