scanning-container-images-with-grype

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill is coherent with its stated purpose and mostly uses legitimate Anchore tooling, but it still carries meaningful risk because it gives an AI agent security-scanning capability and includes an unpinned curl|sh installer. No strong signs of malware, credential theft, or deceptive data routing were found.

Confidence: 88%Severity: 72%
Audit Metadata
Analyzed At
Apr 10, 2026, 08:33 AM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Fscanning-container-images-with-grype%2F@e403002f40e36a1bc187baf7d00a4de779682194