security-headers-generator

Warn

Audited by Socket on May 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s stated purpose is a narrow security-headers helper, but it is granted broad Bash(npm:*) execution authority without any specific install source, package, or need shown in the content. There is no clear credential theft or exfiltration path, so this is not confirmed malware, but the capability footprint is broader than necessary for the claimed task.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
May 4, 2026, 02:30 PM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus-skills%2Fsecurity-headers-generator%2F@fa7b03a131a33af143887445f78be8491c04f06c
Security Audit — socket — security-headers-generator