whoami

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.ko.md

No direct indicators of malware are visible in this fragment (no credentials, no network destinations, no explicit destructive actions). The dominant risk is supply-chain delegation: the workflow repeatedly executes packaged scripts (${CLAUDE_PLUGIN_ROOT}/scripts/honne) that can perform arbitrary local operations, and scan failure stdout/stderr are passed through to the user. Based on this fragment alone, the likelihood of overt malicious payload is low, but the security risk is moderate due to high-privilege local execution and artifact persistence.

Confidence: 62%Severity: 52%
Audit Metadata
Analyzed At
Apr 29, 2026, 02:43 PM
Package URL
pkg:socket/skills-sh/jazz1x%2Fhonne%2Fwhoami%2F@42d2554699f43bee63c8b5af9994bbbf9b4d2ccb