security-audit

Warn

Audited by Socket on Mar 26, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core purpose is coherent for a security-audit skill, but the actual footprint is broad and the most sensitive execution details are hidden in referenced files not provided here. Bash/WebFetch/Agent access, optional external CLI use, and possible transmission of repository-derived data to Gemini create meaningful risk without enough provenance or data-flow constraints to call it benign.

Confidence: 78%Severity: 72%
Audit Metadata
Analyzed At
Mar 26, 2026, 09:26 PM
Package URL
pkg:socket/skills-sh/somnio-software%2Fsomnio-ai-tools%2Fsecurity-audit%2F@5c7c65f924dfbbdf3d2e12fdb783d53caed60601