security-scan

Fail

Audited by Socket on Feb 17, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The file describes a legitimate pre-commit security scanning skill: grep-based secret detection, language-specific vulnerability audits, injection pattern checks, and gating behavior to halt commits on critical findings. There is no direct evidence of malware or obfuscated payloads in the provided content. The primary concerns are operational: an explicit prohibition on manual scans (which discourages independent verification) and the reliance on third-party tooling/containers (which should be pinned and audited). Recommend: allow use after removing or clarifying the prohibition on manual scanning, pin and document versions/digests for any third-party containers/tools, and make halt policies auditable and configurable.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 17, 2026, 07:55 AM
Package URL
pkg:socket/skills-sh/meriley%2Fclaude-code-skills%2Fsecurity-scan%2F@bdf696701a395749fb189f9890ab923e1d93ce60