ghost-scan-code

Warn

Audited by Socket on Sep 29, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is largely coherent for a code-security scanner and does not show credential theft, hidden exfiltration, or malicious installers. The main risks are that it empowers agentic security scanning and introduces transitive trust in an unspecified `repo-context` skill; the official Claude CLI dependency appears legitimate and same-org, keeping this below malicious.

Confidence: 88%Severity: 68%
AnomalyLOW
scripts/loop.sh

This is an orchestration script for dispatching Claude-based scanning workers over files and tracking unfinished work. It contains no clear malware or direct data exfiltration. The principal risks are prompt injection and path traversal through the unvalidated prompt argument, because the external claude process receives write-capable tools and follows a dynamically selected instruction file. The supplied code also contains an apparent syntax error at the final echo statement, which would prevent execution. Review and constrain prompt, path, and input values before use, and fix the unterminated quote.

Confidence: 98%Severity: 58%
Audit Metadata
Analyzed At
Sep 29, 2026, 05:28 AM
Package URL
pkg:socket/skills-sh/ghostsecurity%2Fskills%2Fghost-scan-code%2F@795def215be62d4999d09bea7996756f09df093a45ee18b5d6a62153da337a7e
Security Audit — socket — ghost-scan-code