http-header-security-audit
Warn
Audited by Socket on May 4, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The stated purpose is a benign HTTP header security audit helper, but the skill grants broad Bash(npm:*) execution without any specific trusted package, pinned version, or documented need. There is no clear evidence of malware or credential theft, yet the capability footprint is broader than the purpose and creates meaningful supply-chain and execution risk.
Confidence: 87%Severity: 72%
Audit Metadata