sast-fileupload

Warn

Audited by Socket on Apr 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is internally consistent and does not show credential theft, exfiltration, or installer abuse, but it materially expands an AI agent’s offensive security capability by directing autonomous vulnerability discovery across a codebase. Risk comes from enabling security scan behavior and processing untrusted code with subagents, not from malware-like behavior.

Confidence: 89%Severity: 62%
Audit Metadata
Analyzed At
Apr 8, 2026, 08:01 AM
Package URL
pkg:socket/skills-sh/utkusen%2Fsast-skills%2Fsast-fileupload%2F@b270bb26c1c5f2e04d810ec35d735804994ba2e5