safha

Warn

Audited by Socket on Jul 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated capabilities are coherent for an Arabic scraping/NLP skill, and no direct credential theft or covert exfiltration is shown. However, the core safha executable is not verifiably sourced from an official package, repo, or release channel in the provided evidence, so the skill carries high supply-chain risk disproportionate to the trust information available.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
Jul 7, 2026, 07:16 AM
Package URL
pkg:socket/skills-sh/Moshe-ship%2Fhurmoz%2Fsafha%2F@c05d35e6b6360f2136516f24bba2da7abe9ca7bec267b0c5b129c945d131a221
Security Audit — socket — safha