skill-protocol-mastery

Fail

Audited by Socket on Mar 12, 2026

3 alerts found:

Obfuscated Filex3
Obfuscated FileHIGH
examples/standard-skill/SKILL.md

The Code Analyzer skill is coherently aligned with its stated purpose. It uses appropriate read-only tooling to discover and inspect code, searches for patterns, and reports findings without modifying the source. The lack of network activity and credentials use aligns with a benign static analysis capability. Potential improvements include adding optional redaction of sensitive literals in reports and supporting incremental analysis for large repositories.

Confidence: 98%
Obfuscated FileHIGH
examples/complete-skill/SKILL.md

The skill is coherently scoped to its stated purpose of analyzing, populating, and validating fillable PDF forms. It relies on standard, verifiable dependencies from PyPI and operates primarily on local files (PDFs and JSON mappings) without network communication or credential handling. Data flows and permissions are proportionate to the task, and there are no evident insecure practices (no hard-coded secrets, no TLS bypass, no unauthorized data sinks). Overall, the skill appears Benign with low security risk; remains Suspicious only for any hidden behaviors not visible in the provided description, but based on the material, it aligns well with its stated purpose.

Confidence: 98%
Obfuscated FileHIGH
SKILL.md

The skill-protocol-mastery artifact presents a coherent, well-scoped, and documentation-focused guidance tool for skill creation and validation. There are no evident data exfiltration paths, credential handling, or untrusted download/execution patterns. The security posture appears benign, with a low-to-moderate risk profile driven primarily by the potential for misinterpretation if users blindly execute scripts or modify critical skill structures without verification. Overall, the footprint aligns with its stated purpose as a design and validation guide rather than an executable agent utility.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 12:06 PM
Package URL
pkg:socket/skills-sh/rafaelcalleja%2Fclaude-market-place%2Fskill-protocol-mastery%2F@a062c40c116fa38d5d321add6d8feebb3e8e7d44