security-investigator-automation
Warn
Audited by Socket on Jun 12, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
The skill is mostly coherent with its stated defensive investigation purpose: it uses expected Microsoft security data sources, KQL, and threat-intelligence enrichment. Main concerns are moderate supply-chain trust from a GitHub clone with publisher/repo-owner mismatch, broad credentialed access across multiple security systems, and optional routing of investigation data to third-party TI services. Overall this looks suspicious-to-moderate risk rather than malicious.
Confidence: 100%Severity: 60%
Audit Metadata