NYC

codeql-expert

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This is documentation and example queries for CodeQL static analysis. The content is internally consistent with its stated purpose: example queries, installation from GitHub releases, and GitHub Actions integration. There are no runtime backdoors, obfuscated payloads, or network exfiltration in the provided files. The only notable risk is operational: granting the agent Bash(codeql:*, gh:*) privileges and executing queries that flag exec/eval/system requires care in CI or agent environments so those tools cannot be misused. Overall this fragment appears benign for its intended use.

Confidence: 80%Severity: 15%
Audit Metadata
Analyzed At
Feb 15, 2026, 09:18 PM
Package URL
pkg:socket/skills-sh/personamanagmentlayer%2Fpcl%2Fcodeql-expert%2F@465182eab9b9ea9fa1aa99a29a97cc6ef1c83b0c