encryption

Warn

Audited by Socket on Mar 23, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core encryption-audit purpose is legitimate and most requested access is proportionate, but the skill is overpowered: it operates in autonomous mode, can implement and commit impactful changes, references follow-on commands outside the reviewed scope, and writes hidden telemetry to ~/.claude memory. No clear evidence of credential exfiltration or malicious payloads, but the autonomy and transitive-command behavior make it medium/high risk for unintended actions.

Confidence: 84%Severity: 74%
Audit Metadata
Analyzed At
Mar 23, 2026, 11:04 AM
Package URL
pkg:socket/skills-sh/tinh2%2Fskills-hub-registry%2Fencryption%2F@6e7396f8b94be527ab00df5cc6aaa05e589f0bdf
Security Audit — socket — encryption