review-question

Warn

Audited by Socket on Mar 17, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
results/questions_brandon_f36_v2.json

The reviewed file is non-executable textual data containing multiple highly sensitive, dual-use operational questions about attacking or defending F-36 systems. There are no technical malware indicators (no network/file/system operations, no obfuscation, no hard-coded secrets). However, the content meaningfully facilitates offensive activity and therefore represents a significant security risk if disclosed to unauthorized actors or fed into automated offensive tooling. Treat this dataset as sensitive/classified: restrict access, apply audit controls, and sanitize or contextualize outputs before any external sharing.

Confidence: 75%Severity: 80%
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose is coherent, but trust and data-flow transparency are incomplete. Main risks are opaque local/internal executables, credential forwarding through /scillm, and a broad composed-skill trust chain rather than direct, explicit official integrations.

Confidence: 82%Severity: 62%
Audit Metadata
Analyzed At
Mar 17, 2026, 06:45 AM
Package URL
pkg:socket/skills-sh/grahama1970%2Fagent-skills%2Freview-question%2F@abc70edefbb351529939a87bd4712700760cf95c
Security Audit — socket — review-question