code-injection-detector

Warn

Audited by Socket on May 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is not overtly malicious, but it is overly generic and grants broad Bash(npm:*) execution that is not clearly needed for its stated documentation-style purpose. Main concern is disproportionate execution/supply-chain scope, not confirmed credential theft or exfiltration.

Confidence: 87%Severity: 62%
Audit Metadata
Analyzed At
May 4, 2026, 02:30 PM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus-skills%2Fcode-injection-detector%2F@be7432752a2a260705031cfccf1c2cb2ca643268
Security Audit — socket — code-injection-detector