security-headers

Warn

Audited by Socket on Feb 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Backtick command substitution detected All findings: [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] data_exfiltration: Outbound data post or form upload via curl/wget detected (NW002) [AITech 8.2.3] This skill is coherent with its stated purpose: it fetches HTTP headers, analyzes them, and generates framework-specific header configurations. There are no clear signs of malicious intent. The main security considerations are standard: npm dependency installation (pin versions), accepting arbitrary URLs for curl (validate inputs), and the cross-skill shared cache / filesystem writes which increase attack surface and risk of unintended data exposure. Recommend adding explicit warnings/consent for file writes, pinning npm package versions, and restricting or documenting cache sharing access. LLM verification: This skill appears to be a legitimate security-headers utility: its capabilities align with the stated purpose (checking headers and generating configurations). Primary risks are supply-chain and privacy-related rather than outright malicious code: unpinned npm install of helmet, use of curl to send the inspected URL to third-party scanners (potential data leak), and a shared/indefinitely-lived cache across skills that increases attack surface if compromised. There is a minor doc/code inconsiste

Confidence: 90%Severity: 75%
Audit Metadata
Analyzed At
Feb 21, 2026, 12:27 PM
Package URL
pkg:socket/skills-sh/manastalukdar%2Fclaude-devstudio%2Fsecurity-headers%2F@9329ee1556d6f85633295aa0f32f323db8afd4ce