action-validator

Warn

Audited by Socket on May 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s stated purpose is advisory validation, but it also teaches a concrete method to bypass sensitive-path permission controls on `.claude/` using `/tmp` and Bash so the copy is not audited. There is no clear credential theft or external exfiltration, but the control-evasion guidance is materially inconsistent with a safety validator’s role and creates high local security risk.

Confidence: 89%Severity: 84%
Audit Metadata
Analyzed At
May 15, 2026, 06:19 PM
Package URL
pkg:socket/skills-sh/baekenough%2Foh-my-customcode%2Faction-validator%2F@d0d5ae2086715948bbee518d07e085f9f9e1f730
Security Audit — socket — action-validator