security-scan

Warn

Audited by Socket on Apr 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and capabilities are broadly aligned, and the named scanners are mostly legitimate official tools, but trust is reduced because the real behavior is hidden in local scripts that can auto-install tooling with unspecified sources and versions. No explicit credential harvesting or exfiltration appears in the visible skill text, so this looks more like a medium/high-risk security automation skill than confirmed malware.

Confidence: 85%Severity: 68%
Audit Metadata
Analyzed At
Apr 26, 2026, 08:24 PM
Package URL
pkg:socket/skills-sh/mehdic%2Fbazinga%2Fsecurity-scan%2F@76f9e1c2c3ec41aef6af571c46bff6982ce7dcdc
Security Audit — socket — security-scan