security-audit

Warn

Audited by Socket on Mar 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent for a security-audit purpose, but it intentionally enables an AI agent to run security assessment workflows against arbitrary projects and repositories. No credential theft or exfiltration is evident in the text, yet the combination of repo scanning and script execution makes it a high-risk security capability for an agent.

Confidence: 82%Severity: 72%
Audit Metadata
Analyzed At
Mar 16, 2026, 08:37 AM
Package URL
pkg:socket/skills-sh/netresearch%2Fsecurity-audit-skill%2Fsecurity-audit%2F@188a6cda0371de703da53afa6939d93ca1700556