env-secret-detector

Warn

Audited by Socket on May 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s stated purpose is generic and benign-seeming, but it is paired with broad filesystem access and wildcard npm-backed shell execution that is not concretely scoped to a named tool or workflow. There is no direct evidence of credential theft or malicious exfiltration, but the capability footprint is broader than the description justifies, creating meaningful supply-chain and command-execution risk.

Confidence: 87%Severity: 66%
Audit Metadata
Analyzed At
May 4, 2026, 02:30 PM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus-skills%2Fenv-secret-detector%2F@47b9c62d1e0e8ad06ea308d74aca8e683e5f8499
Security Audit — socket — env-secret-detector