http-header-security-audit

Warn

Audited by Socket on May 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The stated purpose is a benign HTTP header security audit helper, but the skill grants broad Bash(npm:*) execution without any specific trusted package, pinned version, or documented need. There is no clear evidence of malware or credential theft, yet the capability footprint is broader than the purpose and creates meaningful supply-chain and execution risk.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
May 4, 2026, 02:30 PM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus-skills%2Fhttp-header-security-audit%2F@c157b160b70b41eaa6e29ae59664c5da0653282b