security-investigator-automation

Warn

Audited by Socket on Jun 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is mostly coherent with its stated defensive investigation purpose: it uses expected Microsoft security data sources, KQL, and threat-intelligence enrichment. Main concerns are moderate supply-chain trust from a GitHub clone with publisher/repo-owner mismatch, broad credentialed access across multiple security systems, and optional routing of investigation data to third-party TI services. Overall this looks suspicious-to-moderate risk rather than malicious.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 12, 2026, 08:53 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Fsecurity-skills%2Fsecurity-investigator-automation%2F@fbd6cea8ec830fae71d975fb3a3adf5c13a67113fd1a9a978f1a50fdc62417af
Security Audit — socket — security-investigator-automation