php-audit-pipeline

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

BENIGN for intent coherence but HIGH-RISK as an AI-agent capability. The skill’s footprint matches its stated purpose: it is a documentation/methodology pipeline for PHP security auditing, with no embedded installer, no credential requests, no third-party proxy endpoints, and no executable payload in the supplied body. However, it explicitly equips an AI agent to perform offensive-style security analysis across codebases, and if paired with broad file-write/command tools it could be misused against unintended targets. Main concern is capability class, not malware or credential theft.

Confidence: 89%Severity: 72%
Audit Metadata
Analyzed At
Sep 17, 2026, 01:01 AM
Package URL
pkg:socket/skills-sh/0xshe%2Fphp-code-audit-skill%2Fphp-audit-pipeline%2F@2920943f25a2457161d9a31711d5ac49cf9589a7b0b27cb4db1ebfe8b7dfec0a
Security Audit — socket — php-audit-pipeline