security-audit

Warn

Audited by Socket on Mar 25, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose is coherent for a security-audit skill, but the real execution footprint is partly hidden in referenced instruction files, and the skill grants broad agent powers (Bash, WebFetch, Agent) to perform offensive-adjacent security scanning. There is no clear evidence of credential theft or malware, but install trust and execution scope are insufficiently transparent.

Confidence: 82%Severity: 62%
Audit Metadata
Analyzed At
Mar 25, 2026, 05:40 PM
Package URL
pkg:socket/skills-sh/somnio-software%2Ftechnology-tools%2Fsecurity-audit%2F@f573679d94dcf5222075985459bf1c8a34089a20