building-threat-feed-aggregation-with-misp
Warn
Audited by Socket on Mar 16, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s purpose is coherent and most data flows are expected for MISP/SIEM integration, but trust and transport security are weakened by a non-current Docker image source, unpinned mutable tags, and disabled TLS verification. No clear credential harvesting or malicious exfiltration is present, but the examples create meaningful deployment and interception risk.
Confidence: 89%Severity: 58%
Audit Metadata