scan

Warn

Audited by Socket on May 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: core repo-scanning and doc-generation behavior is coherent with the stated purpose, but the skill also instructs installation of unrelated third-party plugins and converts untrusted codebase content into `AGENTS.md`, an influential downstream instruction file. No direct credential theft or exfiltration is evident, so this is better classified as medium-risk vulnerable/suspicious rather than malicious.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
May 11, 2026, 11:35 PM
Package URL
pkg:socket/skills-sh/wshobson%2Fagents%2Fscan%2F@adbdc6601af15f8c46b7f1b4d6b19723a63a804e