security-scan

Fail

Audited by Socket on Feb 28, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The manifest itself is documentation for a legitimate security orchestration tool and contains no direct evidence of malware. However, it describes workflows that, if implemented without secure controls, create supply-chain and data-exposure risks: download-and-execute of scripts or scanner installers, improper handling of API credentials, and leaking sensitive findings to external services (including LLM APIs). Recommend auditing the actual scripts and orchestration code before use: require artifact signing/pinning, use secrets managers and least-privilege credentials, implement strict redaction and access control for reports, avoid sending raw scanner outputs to external LLMs, and run scanners in isolated environments. With these mitigations, the tool is usable and valuable for security scanning.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 28, 2026, 10:31 AM
Package URL
pkg:socket/skills-sh/wojons%2Fskills%2Fsecurity-scan%2F@fdd94e234a3a2ebf4395eecb4bd636fa2bceb494