detecting-exposed-secrets-files

Warn

Audited by Socket on Aug 5, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally consistent as a pentest scanner and does not show credential harvesting, covert exfiltration, or untrusted installer behavior. However, it equips the AI agent with active offensive security scanning against remote targets and broad enough tooling to probe exposed secrets, making it high security risk even if not malware.

Confidence: 90%Severity: 79%
Audit Metadata
Analyzed At
Aug 5, 2026, 09:35 PM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus-skills%2Fdetecting-exposed-secrets-files%2F@565c8ca4fb00b5c1c97e314e3ff5e059d28018e0cd19233f6d1c1c17d20a1bed
Security Audit — socket — detecting-exposed-secrets-files