insecure-source-code-management
Warn
Audited by Socket on Jul 21, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally coherent for authorized source-exposure testing, but it grants an AI agent offensive security capabilities to retrieve sensitive files and repositories, and it encourages transitive skill loading. No clear malware or deceptive exfiltration path is present, but the security risk is high due to exploit-oriented functionality and exposure of real secrets during use.
Confidence: 90%Severity: 78%
Audit Metadata