implementing-devsecops-security-scanning

Warn

Audited by Socket on Apr 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is coherent with its stated DevSecOps purpose and mostly uses official vendor tools, so there is no strong sign of credential theft or hidden exfiltration. However, it enables offensive-capable scanning in an AI-agent context and relies on mutable or outdated third-party action/container references, especially the older Trivy action tag and unpinned Semgrep image, which raises supply-chain and execution-trust risk.

Confidence: 89%Severity: 58%
Audit Metadata
Analyzed At
Apr 20, 2026, 11:34 PM
Package URL
pkg:socket/skills-sh/mukul975%2Fanthropic-cybersecurity-skills%2Fimplementing-devsecops-security-scanning%2F@5d1da9929536febb6c157330c2d04b03a34deb0d