anthropic-cybersecurity-skills

Warn

Audited by Socket on May 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s broad cybersecurity purpose matches many of its capabilities, but it asks users to install a large third-party skill corpus from a personal GitHub repo through a transitive skills mechanism, includes executable helper scripts, and may consume multiple sensitive security-service credentials. No direct exfiltration or overtly malicious payload is visible in the provided top-level skill, but the trust chain and operational scope are too broad to classify as benign.

Confidence: 83%Severity: 74%
Audit Metadata
Analyzed At
May 19, 2026, 04:41 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Fsecurity-skills%2Fanthropic-cybersecurity-skills%2F@970599a2b9c4f62e8242a892c1364bf84bafdd65
Security Audit — socket — anthropic-cybersecurity-skills