trufflehog

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
references/custom-detectors.md

The fragment is primarily legitimate trufflehog scanning documentation and contains no evident malware or obfuscated malicious payload. However, the custom verification configuration creates a high-impact secret disclosure path because captured tokens are POSTed to an external endpoint and TLS verification is explicitly disabled. Treat the endpoint as trusted only after independent validation, remove unsafe: true, and protect or avoid storing scan results in shared temporary locations.

Confidence: 98%Severity: 68%
Audit Metadata
Analyzed At
Sep 15, 2026, 09:58 AM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Ftrufflehog%2F@f7d9289266cfdf38780d5bab1fc11e2f8eca8e7bca7d15a0cc816f6df78430e4
Security Audit — socket — trufflehog