yara-sigs

Warn

Audited by Socket on Apr 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is purpose-aligned and mostly locally scoped, with no obvious credential harvesting or external exfiltration. The main risks are that it is an AI-agent offensive/security-analysis capability, uses unpinned git-cloned rule sets with recursive submodules, and chains into another skill for snapshot collection.

Confidence: 90%Severity: 72%
Audit Metadata
Analyzed At
Apr 11, 2026, 06:42 AM
Package URL
pkg:socket/skills-sh/dariushoule%2Fx64dbg-skills%2Fyara-sigs%2F@80c242b5fa92564a6471237b84569ce18bd0c55f
Security Audit — socket — yara-sigs