audit-plugin

Fail

Audited by Socket on May 24, 2026

2 alerts found:

AnomalyObfuscated File
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose is plausible for an auditing skill, but the actual execution relies on an unverifiable transitive skill/analyzer and gives the agent Bash+Write authority over untrusted plugin content in an iterative fix loop. The main concern is install/execution trust and indirect prompt-injection risk from analyzing arbitrary skills, not confirmed malware.

Confidence: 100%Severity: 60%
Obfuscated FileHIGH
references/acceptance-criteria.md

All provided reports lack the actual code to review, rendering malware/security-risk assessment incomplete. An improved approach is to obtain the code bundle and apply targeted checks against the acceptance criteria, then provide a concrete remediation plan.

Confidence: 90%
Audit Metadata
Analyzed At
May 24, 2026, 08:28 AM
Package URL
pkg:socket/skills-sh/richfrem%2FProject_Sanctuary%2Faudit-plugin%2F@bd4a55f77fd0bd9aa4ab3289f973f12edf9e5165
Security Audit — socket — audit-plugin