supply-chain-audit

Fail

Audited by Socket on Apr 22, 2026

2 alerts found:

SecurityMalware
SecurityMEDIUM
references/supply-chain-attack.md

This file is not a normal dependency implementation; it is an offensive, highly actionable supply-chain attack playbook describing how to execute malicious lifecycle hooks, poison container/image artifacts, inject commands into CI/CD, and exfiltrate build-time secrets via multiple channels. Even without executable code in this fragment, its presence in a package/repo should be treated as strongly suspicious and unsuitable for trusted use.

Confidence: 70%Severity: 78%
MalwareHIGH
SKILL.md

This skill is malicious in purpose and behavior. Its footprint is fundamentally incompatible with a benign supply-chain audit guide because it explicitly instructs registry poisoning, malicious dependency delivery, secret harvesting from build environments, and exfiltration to attacker-controlled hosts.

Confidence: 98%Severity: 99%
Audit Metadata
Analyzed At
Apr 22, 2026, 10:11 AM
Package URL
pkg:socket/skills-sh/wgpsec%2FAboutSecurity%2Fsupply-chain-audit%2F@ccdd30fabadc28a31329b3a9d0d405f12bae7e8f