devsecops-patterns
Warn
Audited by Socket on Apr 7, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill is internally consistent as a DevSecOps guide and mostly uses official tools and expected data flows, but it grants an AI agent meaningful security-testing capability, including active DAST/CVE scanning against live targets. This is high operational risk rather than confirmed malware; the main concerns are offensive security enablement, broad scan scope, and some mutable supply-chain references.
Confidence: 88%Severity: 74%
Audit Metadata