code-security-audit

Warn

Audited by Socket on Apr 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent for a code security audit workflow, but it is inherently high risk because it equips an AI agent with offensive security scanning, command execution, Docker builds, and broad processing of untrusted repository content. No clear credential-harvesting or exfiltration behavior is present, so this is not confirmed malware; the main concern is powerful audit/pen-test capability plus moderate supply-chain and prompt-injection exposure.

Confidence: 88%Severity: 79%
Audit Metadata
Analyzed At
Apr 18, 2026, 02:14 AM
Package URL
pkg:socket/skills-sh/sparkfabrik%2Fsf-awesome-copilot%2Fcode-security-audit%2F@4686999888de7bf7efb56f5154b535dea39a496a
Security Audit — socket — code-security-audit