socket
Pass
Audited by Gen Agent Trust Hub on Jul 11, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions to execute the
socketCLI tool. It uses shell commands to scan individual packages (socket npm/<package-name>) and perform full project scans (socket scan create). - [DATA_EXFILTRATION]: Using the
socketscanning tool involves transmitting package manifest information and dependency metadata to the Socket.dev platform for analysis. This is the expected and documented behavior of a security scanning service. - [PROMPT_INJECTION]: The skill provides decision guidance for the agent to evaluate package safety (e.g., checking vulnerability and supply chain scores). These are standard instructional parameters for a security utility and do not attempt to bypass agent safety protocols.
Audit Metadata