security-auditor

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/detect-secrets.sh

This is a defensive secret-scanning utility with no clear malicious payload or supply-chain backdoor. However, the use of eval with user-controlled TARGET_DIR creates a genuine command-injection risk if the script is invoked with an attacker-controlled or specially crafted path. Replace eval with find arguments constructed as an array, and validate or safely quote all paths. The output path should also be handled carefully to avoid unintended overwrites.

Confidence: 98%Severity: 68%
Audit Metadata
Analyzed At
Sep 17, 2026, 04:08 AM
Package URL
pkg:socket/skills-sh/curiositech%2Fsome_claude_skills%2Fsecurity-auditor%2F@1a7a9d216cf4edf4579ac2c3e4d04bc4f1ed80e6c674e660318cdc3360d51877
Security Audit — socket — security-auditor