esaa-security-audit
Warn
Audited by Socket on May 24, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
The skill is broadly aligned with its stated purpose as a code security auditing framework, but it carries medium risk due to supply-chain trust gaps, external LLM data flow, and untrusted-code analysis by an agentic system. The main concern is not clear malicious behavior; it is the combination of a publisher/source mismatch, direct execution of repo code, and credential-backed processing of potentially sensitive repositories.
Confidence: 100%Severity: 60%
Audit Metadata