sysdig-posture

Warn

Audited by Socket on May 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities largely match its stated Terraform/Posture-authoring purpose and its credential handling is proportionate, but it introduces medium supply-chain risk by directing installation of an external MCP server through an unpinned `npx` path that does not match the indexed official install methods for the Sysdig-owned project. No clear malicious behavior or credential exfiltration is present in the skill itself.

Confidence: 89%Severity: 56%
Audit Metadata
Analyzed At
May 12, 2026, 10:54 PM
Package URL
pkg:socket/skills-sh/sysdig%2Fskills%2Fsysdig-posture%2F@3ac838e8a4b471d927de4750df9910704b5d3c32