insecure-source-code-management

Warn

Audited by Socket on Jul 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent for authorized source-exposure testing, but it grants an AI agent offensive security capabilities to retrieve sensitive files and repositories, and it encourages transitive skill loading. No clear malware or deceptive exfiltration path is present, but the security risk is high due to exploit-oriented functionality and exposure of real secrets during use.

Confidence: 90%Severity: 78%
Audit Metadata
Analyzed At
Jul 21, 2026, 01:26 PM
Package URL
pkg:socket/skills-sh/strivepan-svg%2Fhack-skills%2Finsecure-source-code-management%2F@c3575dfc003a81d1b16effcae05599b9f06d53f3dcf64758dcfc100753dd82b4
Security Audit — socket — insecure-source-code-management