claude-md-auditor

Warn

Audited by Socket on Apr 4, 2026

1 alert found:

Security
SecurityMEDIUM
examples/test_claude_md_with_issues.md

No malware logic is present in the provided fragment because it contains no executable code. However, it embeds plaintext credentials (an API key-like token and a Postgres connection string with username/password and internal IP). This is a serious supply-chain hygiene and incident risk: rotate/revoke exposed secrets and remove them from versioned artifacts; then search the repo/CI for any downstream usage of these values.

Confidence: 70%Severity: 80%
Audit Metadata
Analyzed At
Apr 4, 2026, 01:31 PM
Package URL
pkg:socket/skills-sh/cskiro%2Fclaudex%2Fclaude-md-auditor%2F@a15260e34b9eb172456e1cc6601ef3483ab467b0
Security Audit — socket — claude-md-auditor