performing-container-security-scanning-with-trivy

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill is internally consistent and uses official Aqua Security distribution paths, so it is not malware-like. However, it equips an AI agent with real security scanning capabilities against images, filesystems, and Kubernetes environments, which is high-risk tooling by category; combined with Docker/cluster access and optional curl|sh install hygiene, this warrants a high security-risk classification despite coherent purpose.

Confidence: 91%Severity: 74%
Audit Metadata
Analyzed At
Apr 10, 2026, 06:28 PM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Fperforming-container-security-scanning-with-trivy%2F@00debcbb1eb0c2fb3bb1f82e8dffa41915af0303