hardcoded-credential-finder

Warn

Audited by Socket on May 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s stated purpose is benign, but its footprint is not well-scoped because a generic credential-finder guide is given broad Bash(npm:*) execution without any package pinning or provenance constraints. There is no explicit credential theft or exfiltration, so this looks more like overbroad capability and supply-chain risk than malware.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
May 4, 2026, 02:30 PM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus-skills%2Fhardcoded-credential-finder%2F@22767750d2d7513bb724554d502165ba581e93df