prowler-attack-paths-query
Fail
Audited by Socket on Mar 12, 2026
1 alert found:
Obfuscated FileObfuscated FileSKILL.md
HIGHObfuscated FileHIGH
SKILL.md
Overall, the skill appears benign and coherent with its stated purpose of generating and organizing openCypher Attack Paths queries for cloud infrastructure graphs. It relies on open data sources and internal Cartography schema references to craft provider-scoped queries and always includes Prowler findings in the results. The main potential risk is reliance on external JSON indexes (pathfinding.cloud) for path definitions, which could affect stability if the remote data changes, but this does not imply credential leakage or malicious activity. No evidence of credential access, data exfiltration, unauthorized installs, or autonomous real-world actions is observed in the provided content.
Confidence: 98%
Audit Metadata