cti-domain-research

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is mostly aligned with its stated CTI research purpose, but it carries medium risk because it combines untrusted web research with Bash access and optionally forwards data into a separate unreviewed NotebookLM connector plugin. Nothing here confirms malware, but the transitive plugin trust and prompt-injection exposure make it suspicious rather than fully benign.

Confidence: 79%Severity: 58%
Audit Metadata
Analyzed At
Apr 29, 2026, 03:41 PM
Package URL
pkg:socket/skills-sh/SECURITY-PHOENIX-DEMO%2FSECURITY-SKILLS-CLAUDE-CODE%2Fcti-domain-research%2F@989c043a2703ee02577ccd1deaac2ff8c4b1472a
Security Audit — socket — cti-domain-research