red-team-bundler

Warn

Audited by Socket on Apr 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's capabilities mostly match its stated purpose of creating local review bundles, and it does not request credentials or use remote installers. However, it is an offensive-security workflow that packages potentially sensitive project files for external review, and it executes unreviewed local bundler scripts whose behavior is not visible here, creating moderate security risk without clear evidence of malware.

Confidence: 84%Severity: 61%
Audit Metadata
Analyzed At
Apr 3, 2026, 06:08 PM
Package URL
pkg:socket/skills-sh/richfrem%2Fagent-plugins-skills%2Fred-team-bundler%2F@c1a0c083861b9b3eff30120cc054456bf5488b64