security-scan

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core purpose and local scanning behavior are broadly consistent with a security-scan skill, and there is no explicit credential theft or external exfiltration in the provided text. However, delegating fixes to an unpinned community 'fuse-ai-pilot:sniper' subagent creates a transitive trust risk, and the skill processes untrusted code while executing local scripts. Medium security risk, but not confirmed malware.

Confidence: 81%Severity: 56%
Audit Metadata
Analyzed At
Apr 10, 2026, 06:24 AM
Package URL
pkg:socket/skills-sh/fusengine%2Fagents%2Fsecurity-scan%2F@46a6ea7554ce2a45bcdd55548b0025ed72fc0103