incident-response-report

Warn

Audited by Socket on Apr 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill's stated purpose is legitimate and mostly well-scoped, but it depends on executing unverifiable root-path scripts for IP enrichment. The main risk is install/execution trust and unknown data flow inside those scripts, not clear evidence of malicious intent in the reporting instructions themselves.

Confidence: 85%Severity: 78%
Audit Metadata
Analyzed At
Apr 20, 2026, 09:08 AM
Package URL
pkg:socket/skills-sh/crtvrffnrt%2Fskills%2Fincident-response-report%2F@0a3bbda5a3270812302b19a016a8f21abe6fa759