security-scanner

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is internally coherent for a security-scanning purpose and mostly uses official tools and endpoints, but it equips an AI agent with offensive-capable scanning/DAST workflows and includes a few unpinned remote install/execute patterns. This is not credential theft or clear malware, but it is a high-impact security skill that should be treated as risky and used only with explicit user authorization and tight execution controls.

Confidence: 89%Severity: 68%
Audit Metadata
Analyzed At
Mar 15, 2026, 11:11 AM
Package URL
pkg:socket/skills-sh/HouseGarofalo%2Fclaude-code-base%2Fsecurity-scanner%2F@8035010e47aff980ac2c702e9e2b07239336d9f8