semgrep
Warn
Audited by Socket on Jul 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally coherent for a Semgrep scanning tool and uses an official Semgrep install path, but it still grants an AI agent security-testing capability and instructs it to clone and use many unpinned third-party GitHub rulesets. This is not confirmed malware, yet it carries meaningful security risk from offensive-tool enablement and third-party supply-chain exposure.
Confidence: 90%Severity: 76%
Audit Metadata