ccc-security

Warn

Audited by Socket on Apr 1, 2026

4 alerts found:

AnomalySecurityx3
AnomalyLOW
SKILL.md

SUSPICIOUS. The top-level skill is mostly a router and is broadly aligned with a security-audit purpose, but it asks the agent to operate across a full security domain and to load unseen sub-skills. With no concrete install steps, credential handling, or data flows shown here, there is no evidence of confirmed malware; the main risk is transitive trust and the high-impact nature of downstream security capabilities.

Confidence: 82%Severity: 58%
SecurityMEDIUM
security-audit/SKILL.md

The skill is internally consistent with its stated purpose and shows no installer, credential-harvesting, or exfiltration behavior. However, it equips the agent to perform offensive security testing against applications, so it should be treated as a high-risk security capability rather than malware.

Confidence: 90%Severity: 76%
SecurityMEDIUM
owasp-top-10/SKILL.md

SUSPICIOUS: the skill is internally consistent and not malicious, but it is a security/exploit-oriented skill that equips an AI agent to probe applications for vulnerabilities. There are no credential-harvesting, exfiltration, or supply-chain concerns; the main risk is granting offensive security testing capability to an agent.

Confidence: 92%Severity: 74%
SecurityMEDIUM
variant-analysis/SKILL.md

BENIGN for internal consistency but HIGH-RISK as a security capability: the skill's actions match its stated purpose, uses only local search/reporting plus optional official CodeQL, and does not request credentials or exfiltrate data. The main concern is that it gives an AI agent offensive-style vulnerability discovery capability across a codebase.

Confidence: 94%Severity: 72%
Audit Metadata
Analyzed At
Apr 1, 2026, 05:37 AM
Package URL
pkg:socket/skills-sh/KevinZai%2Fcc-commander%2Fccc-security%2F@1a26b45f167b76f90dc91dd384172de44d71e45a
Security Audit — socket — ccc-security