discover

Fail

Audited by Socket on Mar 11, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
operations/github-ecosystem-search.md

The code fragment represents a benign, documentation-backed Bash workflow for ecosystem mapping within a GitHub organization, driven by discovered signals. It purposefully relies on the gh CLI and external API data, with awareness of rate limits and potential privacy concerns. Improvement opportunities include formal input validation for DISCOVERED_NAMES, explicit output-sanitization controls, and configurable logging to minimize sensitive data exposure. Overall, the approach is sound for supply-chain risk analysis with moderate operational risk.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 11, 2026, 10:41 AM
Package URL
pkg:socket/skills-sh/jschulte%2Fclaude-plugins%2Fdiscover%2F@87967f8b76be5697cdc8c694428e66405868d430