semgrep
Warn
Audited by Socket on Sep 14, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s capabilities mostly match its stated purpose as a Semgrep scanning workflow, and there is no clear credential theft or hidden exfiltration. However, it materially expands trust by requiring default use of numerous unpinned third-party GitHub rulesets and external CLIs, which is proportionate to static analysis but still a meaningful supply-chain risk.
Confidence: 90%Severity: 62%
Audit Metadata