storage-analyzer

Warn

Audited by Socket on Jun 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is mostly local and avoids external data flows, so it does not look like malware or credential theft. However, its core behavior is internally inconsistent: it repeatedly promises read-only analysis while defaulting to a localhost server that can trash or permanently delete files based on agent-produced classifications, including on an untested Windows path. That mismatch and destructive local capability make it medium security risk.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 12, 2026, 09:15 PM
Package URL
pkg:socket/skills-sh/kkkkhazix%2Fkhazix-skills%2Fstorage-analyzer%2F@f0bf093988de2af2b4a2b710a75ebb7f1c473143878263ce2fdb8e8ad4bc8a7b
Security Audit — socket — storage-analyzer