codeql

Warn

Audited by Socket on May 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is internally consistent with its stated purpose as a CodeQL analysis guide and shows no credential harvesting, covert behavior, or malicious data routing. Risk comes mainly from granting an AI agent offensive-capable security scanning behavior plus broad local bash/read/write access; supply-chain and exfiltration concerns are otherwise low because the skill itself does not install tools or forward secrets.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
May 11, 2026, 10:20 PM
Package URL
pkg:socket/skills-sh/mwathiben%2Fhush-private-bookmarks%2Fcodeql%2F@d50434f4217c1f61759169c247270fc6912d1735
Security Audit — socket — codeql