engineering-security-engineer

Warn

Audited by Socket on Apr 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s stated purpose is coherent with its capabilities and it is largely a benign instructional security-engineering guide, but the included CI/CD examples weaken trust by recommending mutable GitHub Actions, especially `trivy-action@master` with documented compromise history. No direct credential harvesting, hidden execution, or disproportionate access appears in the skill itself; the main risk is supply-chain exposure if users copy the workflow examples verbatim.

Confidence: 90%Severity: 64%
Audit Metadata
Analyzed At
Apr 7, 2026, 02:26 AM
Package URL
pkg:socket/skills-sh/sahiixx%2Fagency-agents%2Fengineering-security-engineer%2F@adcb510eb1cf578437533b9f13c6b9d105504ad9
Security Audit — socket — engineering-security-engineer