0day-scanner

Warn

Audited by Socket on Sep 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose and capabilities mostly align for a security-review tool, and there are no installers, credential-file reads, or obvious exfiltration endpoints. Risk comes from offensive security functionality plus unclear data routing: scanned code and findings may be sent to unspecified internal REST/MCP services and stored in an unspecified DB/graph, while the skill processes untrusted repo content in a tool-using workflow. This is not confirmed malware, but it is a medium-risk skill with unverifiable backend ownership and persistence behavior.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Sep 18, 2026, 03:59 AM
Package URL
pkg:socket/skills-sh/security-phoenix-demo%2Fsecurity-skills-claude-code%2F0day-scanner%2F@74147d89a4f2360a81e44fcd8be1853e23b897e3bb1bde9a087321c9295abac9
Security Audit — socket — 0day-scanner