post-patch-validation

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent and not overtly malicious, but it equips an AI agent to perform exploit-driven security validation and execute untrusted local code with broad local effects. Supply-chain trust is mostly acceptable, and data flows appear local-only, yet the offensive testing capability plus Bash/Workflow execution makes it high risk.

Confidence: 88%Severity: 72%
Audit Metadata
Analyzed At
Sep 15, 2026, 07:43 AM
Package URL
pkg:socket/skills-sh/trailofbits%2Fskills%2Fpost-patch-validation%2F@0ae8f2b4abb01ec63f2f4ceabe4c974b4d5c2d0b4cda54a47da91d3061fc3e3b
Security Audit — socket — post-patch-validation