devsecops-patterns

Warn

Audited by Socket on Apr 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill is internally consistent as a DevSecOps guide and mostly uses official tools and expected data flows, but it grants an AI agent meaningful security-testing capability, including active DAST/CVE scanning against live targets. This is high operational risk rather than confirmed malware; the main concerns are offensive security enablement, broad scan scope, and some mutable supply-chain references.

Confidence: 88%Severity: 74%
Audit Metadata
Analyzed At
Apr 7, 2026, 10:33 AM
Package URL
pkg:socket/skills-sh/marvinrichter%2Fclarc%2Fdevsecops-patterns%2F@aa56344c74c285fff1ad3e02bafbdee324b5e43c
Security Audit — socket — devsecops-patterns