code-review-secrets-detection
Warn
Audited by Socket on Sep 20, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
The skill is coherent with its stated purpose, but that purpose is an offensive secrets-discovery workflow for an AI agent. No clear credential-harvesting or hidden exfiltration is present, yet the skill enables network scanning, repo dumping, and live credential validation, and it depends partly on third-party tooling with mixed install trust. Overall this is better classified as suspicious/high-risk security tooling rather than malware.
Confidence: 87%Severity: 62%
Audit Metadata