appsec

Warn

Audited by Socket on Aug 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s stated purpose is coherent with security scanning and SBOM generation, and syft/trivy themselves are legitimate tools, but the actual trust anchor is an undocumented required CLI (skill-gate) plus a repo-local shell script. That unverifiable execution path is disproportionate unless the publisher/source relationship is documented. The optional second-brain integration also leaves external data flows unclear.

Confidence: 86%Severity: 76%
Audit Metadata
Analyzed At
Aug 18, 2026, 07:16 PM
Package URL
pkg:socket/skills-sh/lucas-ataides%2Fskills%2Fappsec%2F@2a968bae5a88a669f06fa7b18a2b5cd2edefe8fbd36674480eac32099806845f
Security Audit — socket — appsec