project-analyze

Fail

Audited by Socket on Jul 7, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
phases/02-project-exploration.md

This orchestration code is not overtly malicious code, but it represents a medium-high supply-chain data-exfiltration risk. It composes prompts that require scanning the repository, uses external LLM CLIs inside agents, and writes raw exploration outputs which are later embedded and sent to analysis agents. Without safeguards (allowlists, redaction, script integrity checks, minimal scope, and explicit policies preventing secrets export), using this module in sensitive projects can leak credentials or proprietary code to third parties. Recommend blocking or instrumenting agent-executed scans, applying strict allowlists/redaction before writing or sending outputs, verifying helper script integrity, and avoiding automatic remote LLM calls with raw project data.

Confidence: 90%
Audit Metadata
Analyzed At
Jul 7, 2026, 02:48 AM
Package URL
pkg:socket/skills-sh/catlog22%2Fskill-hub%2Fproject-analyze%2F@22731449b8493586ba4375d099991abf03e2116ed473435633f3b5a97051f598
Security Audit — socket — project-analyze