implementing-soar-automation-with-phantom

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is internally coherent and uses official Splunk SOAR patterns, with proportionate credentials and no suspicious installer or exfiltration path. However, it grants an AI agent powerful SOAR capabilities that can autonomously block indicators and, with approval, isolate hosts or disable accounts, making it a high-impact cybersecurity automation skill with meaningful operational risk.

Confidence: 88%Severity: 69%
Audit Metadata
Analyzed At
Apr 10, 2026, 06:27 PM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Fimplementing-soar-automation-with-phantom%2F@98cef818672fb084e21d862e388c7cc7918df685