engineering-threat-detection-engineer
Warn
Audited by Socket on Apr 7, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
The skill is largely aligned with a legitimate detection-engineering purpose and does not show credential theft or hidden exfiltration. However, it meaningfully increases operational risk by granting an AI agent dual-use security workflow capability and by including direct SIEM deployment with TLS verification disabled in the Splunk step. Overall: suspicious/high-vulnerability rather than malicious.
Confidence: 89%Severity: 62%
Audit Metadata