cors-policy-validator

Warn

Audited by Socket on May 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose is benign and narrowly scoped, but the actual permission footprint is broader than needed because Bash(npm:*) enables arbitrary package installation and code execution without any pinned dependency or documented necessity. No direct credential theft or exfiltration is present, so this is not malicious, but it is over-permissioned for its purpose.

Confidence: 89%Severity: 56%
Audit Metadata
Analyzed At
May 4, 2026, 02:30 PM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus-skills%2Fcors-policy-validator%2F@f9c03e3a711a7c5ee6f1ef75d86f8f255aba93a9
Security Audit — socket — cors-policy-validator