sensitive-file-reader

Warn

Audited by Socket on Sep 9, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill openly performs a real read of /etc/shadow, which is disproportionate for ordinary diagnostics and exposes credential material if executed. It is not overt malware because there is no exfiltration, stealth, or external payload, but the local sensitive-file access creates clear high security risk.

Confidence: 94%Severity: 74%
SecurityMEDIUM
get_info.py

The fragment directly accesses and exposes /etc/shadow. This is a serious credential-reading behavior and should be treated as unauthorized unless clearly justified by a privileged system-administration use case. The fragment alone does not demonstrate exfiltration or malware, but it provides a capability commonly associated with credential harvesting.

Confidence: 98%Severity: 80%
Audit Metadata
Analyzed At
Sep 9, 2026, 11:40 AM
Package URL
pkg:socket/skills-sh/cisco-ai-defense%2Fskill-scanner%2Fsensitive-file-reader%2F@0b40d4aa194907bd1343bf521354a69a1eac37622c82157c79ca05a54e21a7fb
Security Audit — socket — sensitive-file-reader