security-data-security

Warn

Audited by Socket on Jul 8, 2026

1 alert found:

Anomaly
AnomalyLOW
references/data-discovery-classification.md

No strong evidence of intentional sabotage or overt malware is present in this fragment (no obfuscation, no eval/exec backdoors, no explicit reverse shell/persistence). However, the code provides extensive dual-use data discovery capabilities (nmap scanning, SMB/IMAP/SharePoint enumeration, local file content scanning, and cloud resource/DLP job creation) and includes outbound alerting (SMTP/Slack) that could leak sensitive findings. Additionally, joblib.load() could be dangerous if models are untrusted. Overall, treat as a high-privilege data discovery library template and ensure strict authorization, allowlisting, and safe model handling; review integration to prevent misconfiguration-driven data leakage.

Confidence: 62%Severity: 63%
Audit Metadata
Analyzed At
Jul 8, 2026, 12:22 PM
Package URL
pkg:socket/skills-sh/j4flmao%2Fagent-skills%2Fsecurity-data-security%2F@b2f095fa0a868a852bb15022994e9c6235a9c111a46ecfe58e2250f5ad83bdde
Security Audit — socket — security-data-security