implementing-cloud-vulnerability-posture-management

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is broadly aligned with CSPM and uses mostly official data flows, so it does not show clear credential theft or malware behavior. However, it gives an AI agent active cloud security scanning capability and some configuration-changing commands, plus unpinned third-party scanner installs, making it a high-security-risk defensive security skill rather than a benign low-risk helper.

Confidence: 84%Severity: 74%
Audit Metadata
Analyzed At
Mar 15, 2026, 09:40 PM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Fimplementing-cloud-vulnerability-posture-management%2F@2eb9faffe6d24c41cceeedaddb86a8c1ed1b47cc