building-vulnerability-scanning-workflow

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is largely coherent and defensive in purpose, with official-looking vendor/API data flows and no obvious exfiltration or malicious installer behavior. However, it meaningfully increases risk by teaching an agent to run security scanning workflows, disables TLS verification in authenticated examples, and forwards Qualys credentials to a third-party client library rather than using direct official API calls.

Confidence: 88%Severity: 64%
Audit Metadata
Analyzed At
Mar 15, 2026, 09:39 PM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Fbuilding-vulnerability-scanning-workflow%2F@00f5249b3f3f1e033f0609d0e78e4cf87825e80b