vps-security-hardening

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s capabilities mostly match its stated VPS-hardening purpose, and installs come mainly from official OS/package-manager sources. However, it requires highly sensitive passwords, encourages temporarily enabling root password SSH, relies on sshpass to automate credentials, and references an unreviewed automation script. Data flows are mostly proportionate, with only optional direct-to-official webhook posting, but the combination of credential handling and high-impact remote admin actions makes this a medium-to-high security risk rather than benign.

Confidence: 87%Severity: 69%
Audit Metadata
Analyzed At
Apr 22, 2026, 07:38 AM
Package URL
pkg:socket/skills-sh/wlzh%2Fskills%2Fvps-security-hardening%2F@1bb04a6f2769d9f029ecefa52a54f991461e9daf