skill-scanner

Warn

Audited by Socket on May 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose mostly matches the read/scan behavior, but the skill hardcodes an API token and transmits full local skill contents to a remote model endpoint whose exact public documentation could not be verified. The main risks are credential handling, external code/data exposure, and recursive analysis of untrusted skill content rather than confirmed malware.

Confidence: 87%Severity: 81%
Audit Metadata
Analyzed At
May 15, 2026, 10:47 AM
Package URL
pkg:socket/skills-sh/bighardperson%2Fcomputer-science-skills-collection%2Fskill-scanner%2F@90989f055915d48b7855ddcfd35af29f6d400fe7
Security Audit — socket — skill-scanner