appsec
Warn
Audited by Socket on Aug 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s stated purpose is coherent with security scanning and SBOM generation, and syft/trivy themselves are legitimate tools, but the actual trust anchor is an undocumented required CLI (skill-gate) plus a repo-local shell script. That unverifiable execution path is disproportionate unless the publisher/source relationship is documented. The optional second-brain integration also leaves external data flows unclear.
Confidence: 86%Severity: 76%
Audit Metadata