security-secrets

Fail

Audited by Socket on Mar 11, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill appears to be coherently scoped for secret-detection within codebases, with redaction and pattern-based scanning aligned to its described use. There are no evident data-exfiltration or credential-forwarding behaviors in the provided description. The main potential risk lies in how reports are exposed (e.g., via logs or CI artifacts) and ensuring that reports themselves do not leak secrets. Overall, the footprint is Benign with moderate caution about report handling and dependency provenance when actually installing/scanning in practice.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 11, 2026, 09:18 AM
Package URL
pkg:socket/skills-sh/justinlevinedotme%2Fjalco-opencode%2Fsecurity-secrets%2F@af9f860234014fbe7083d960803801473c21685e