piv

Warn

Audited by Socket on Aug 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly aligned with its stated orchestration purpose and shows no direct credential theft, exfiltration endpoint, or remote download-execute chain. Main concerns are weaker publisher provenance, autonomous code/commit actions, and prompt-injection exposure from passing project content into sub-agents with write/exec capabilities.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Aug 19, 2026, 07:48 PM
Package URL
pkg:socket/skills-sh/bighardperson%2Fcomputer-science-skills-collection%2Fpiv%2F@982f3ebb5018849a0ed0c209226003fed56ae0b2e0245f1489094f7a1b4e9f6a
Security Audit — socket — piv