incident-response-main

Warn

Audited by Socket on Apr 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s investigative purpose is legitimate and mostly well-scoped, but its mandatory reliance on unverifiable local IP-enrichment scripts creates a significant trust gap. Data appears to flow appropriately to Microsoft via `az rest`, yet the undisclosed shell scripts are core to the workflow and could send investigation data to unknown services. Because those binaries/scripts are not verifiable from the skill, overall risk is high even without evidence of confirmed malware.

Confidence: 88%Severity: 74%
Audit Metadata
Analyzed At
Apr 20, 2026, 09:08 AM
Package URL
pkg:socket/skills-sh/crtvrffnrt%2Fskills%2Fincident-response-main%2F@25d066310b9ad8fb261757ee7eca3f8fdf837fb4