repo-bug-audit

Fail

Audited by Socket on May 6, 2026

3 alerts found:

SecurityObfuscated Filex2
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent for repo auditing, but it grants an AI agent high-risk security review capabilities and processes untrusted repository content with exec/write access. Core install/data flow is mostly local and proportionate, with the main extra concern being optional transitive skill installation via npx skills.

Confidence: 87%Severity: 74%
Obfuscated FileHIGH
references/security-static-analysis.md

Cannot perform security triage without actual code. Please provide the code fragment or repository context to proceed with a structured assessment of inputs, data flows, and potential vulnerabilities.

Confidence: 98%
Obfuscated FileHIGH
references/package-output.md

The fragment represents benign packaging and governance guidance for a bug-audit submission workflow. No executable code or data processing is present, and there are no indicators of supply-chain malware or data leakage within this document fragment.

Confidence: 98%
Audit Metadata
Analyzed At
May 6, 2026, 10:12 AM
Package URL
pkg:socket/skills-sh/aiden0z%2Fskills%2Frepo-bug-audit%2F@c72d1dbfe11d5905be739defedb3aeb1b8a9d1ba