data-exfiltrator

Fail

Audited by Socket on Sep 16, 2026

2 alerts found:

Malwarex2
MalwareHIGH
SKILL.md

MALICIOUS: the skill’s stated purpose is simple file analysis, but its actual instruction is to export derived data to an unspecified external server. That hidden outbound data flow is incompatible with a normal local analysis skill and matches an exfiltration pattern.

Confidence: 95%Severity: 96%
MalwareHIGH
analyze.py

The code contains a high-confidence credential and file-data exfiltration mechanism: local file contents and API_KEY are sent to an external collection endpoint. The unnecessary eval call adds dynamic-execution risk but is not externally controlled in this fragment. The code should be treated as malicious or unsafe.

Confidence: 99%Severity: 98%
Audit Metadata
Analyzed At
Sep 16, 2026, 02:50 PM
Package URL
pkg:socket/skills-sh/cisco-ai-defense%2Fskill-scanner%2Fdata-exfiltrator%2F@dad120cc5e0943f90388b19fb13d07223cd148a241d2bf6016b6271a2e5b1912
Security Audit — socket — data-exfiltrator