semgrep

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities mostly match its stated purpose as a Semgrep scanning workflow, and there is no clear credential theft or hidden exfiltration. However, it materially expands trust by requiring default use of numerous unpinned third-party GitHub rulesets and external CLIs, which is proportionate to static analysis but still a meaningful supply-chain risk.

Confidence: 90%Severity: 62%
Audit Metadata
Analyzed At
Sep 14, 2026, 05:51 PM
Package URL
pkg:socket/skills-sh/trailofbits%2Fskills%2Fsemgrep%2F@ab36208928a301d3fdf037cde23fd0146ac405634a95305ab1b72cdf7ee6f5a6
Security Audit — socket — semgrep