red-handed-audit

Warn

Audited by Socket on Aug 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's stated purpose broadly matches its behavior, but it delegates sensitive transcript and repo inspection to an unpinned third-party npm CLI executed via `npx`. This is not overt malware, yet the install-and-run trust model and unverifiable 'nothing leaves the machine' claim create medium security risk.

Confidence: 84%Severity: 63%
Audit Metadata
Analyzed At
Aug 11, 2026, 01:50 PM
Package URL
pkg:socket/skills-sh/davepoon%2Fbuildwithclaude%2Fred-handed-audit%2F@7cd3edaf3126fc786164e16f66eb5fa1aef167dc16b5551b9d7373fe0c84ce20
Security Audit — socket — red-handed-audit