security-audit-quick

Fail

Audited by Socket on Mar 1, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill is a useful, deterministic grep-based static scanner and does not itself contain malicious code or remote dependencies. The main security concern is operational: the inclusion of Bash in allowed-tools combined with no explicit exclusions for sensitive files increases the risk that an agent (or a malicious prompt) could execute shell commands that read or exfiltrate secrets. If executed in a properly sandboxed, network-isolated environment and with explicit sensitive-path exclusions (and optional masking of matches), the tool is low-risk and valuable. Without those controls, use of this skill in an untrusted runtime presents a moderate security risk.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 1, 2026, 01:37 AM
Package URL
pkg:socket/skills-sh/yusuketsunoda%2Fppt-trans%2Fsecurity-audit-quick%2F@b60e8ad4eb0030ea5b59c66c15b4c046bf24660c