scanning-input-validation-practices

Warn

Audited by Socket on Apr 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s purpose is coherent, but its core scanner dependency is unverifiable and its bash-enabled security permissions are broader than necessary. No direct credential theft or explicit exfiltration is shown, so this is not confirmed malware, but it is a high-risk security-scanning skill with unclear supply-chain provenance.

Confidence: 86%Severity: 78%
Audit Metadata
Analyzed At
Apr 4, 2026, 08:03 PM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus%2Fscanning-input-validation-practices%2F@5f639c856524b4100d3511306229b29241981453