security-scan

Warn

Audited by Socket on Mar 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The description presents a coherent security-audit workflow for Claude Code configurations using a recognized external scanner (AgentShield). It appropriately covers typical assets to inspect, output modalities, and an optional deep-analysis mode that introduces credential handling. Risks mainly center on credential management for Opus mode, automated modification of critical config files, and dependencies on external tooling. Overall, the fragment aligns with its stated purpose, but should emphasize secret handling guarantees, provenance validation for external tools, and explicit user consent/auditing of auto-fixes in automated environments.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 4, 2026, 03:48 PM
Package URL
pkg:socket/skills-sh/Mark393295827%2Fhouse-maint-ai%2Fsecurity-scan%2F@6d73ded3733c37f5fd7637d48a3d44959f7e0f7e