semgrep

Warn

Audited by Socket on Jul 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent for a Semgrep scanning tool and uses an official Semgrep install path, but it still grants an AI agent security-testing capability and instructs it to clone and use many unpinned third-party GitHub rulesets. This is not confirmed malware, yet it carries meaningful security risk from offensive-tool enablement and third-party supply-chain exposure.

Confidence: 90%Severity: 76%
Audit Metadata
Analyzed At
Jul 18, 2026, 12:10 PM
Package URL
pkg:socket/skills-sh/RedHatProductSecurity%2Fprodsec-skills%2Fsemgrep%2F@15bc2a306148df66179719f66bb177119bea8d67214b0543e0784ac8a5a7428c
Security Audit — socket — semgrep