secure

Warn

Audited by Socket on Mar 23, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK but not malicious. The skill is internally coherent for security triage and avoids remote installers or obvious exfiltration, but it gives an AI agent broad autonomous security-review capability, scans secret-bearing files, and can silently write telemetry locally. Main concern is powerful security tooling in autonomous mode, not credential theft or supply-chain deception.

Confidence: 86%Severity: 74%
Audit Metadata
Analyzed At
Mar 23, 2026, 11:05 AM
Package URL
pkg:socket/skills-sh/tinh2%2Fskills-hub-registry%2Fsecure%2F@6039b0fe796282d2d1305bac94c22e0b30e5a1f7
Security Audit — socket — secure