anthropic-cybersecurity-skills

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent as a cybersecurity skill library, but it materially expands trust by instructing installation of another skill/repository through the skills CLI and then encourages loading/executing third-party helper scripts. No direct credential theft or covert exfiltration is shown, so this is not confirmed malware, but the transitive-trust and downstream execution footprint make it a high-risk meta-skill.

Confidence: 88%Severity: 76%
Audit Metadata
Analyzed At
Sep 15, 2026, 09:28 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Fsecurity-skills%2Fanthropic-cybersecurity-skills%2F@bfc521d9c7d4b874d902a53728bcc1a574b4e1e16463b59c6c4e47c4107f9713
Security Audit — socket — anthropic-cybersecurity-skills