path-traversal-finder

Warn

Audited by Socket on May 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose is a vague security-guidance skill, but its actual footprint includes broad Bash(npm:*) execution that can fetch and run arbitrary npm packages without pinning or publisher constraints. No direct malware or exfiltration is shown, but the capability scope is disproportionate and the security-tooling nature raises risk.

Confidence: 87%Severity: 68%
Audit Metadata
Analyzed At
May 4, 2026, 02:30 PM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus-skills%2Fpath-traversal-finder%2F@96153267cb8788d879eaee58c99e7beac9543613
Security Audit — socket — path-traversal-finder