Check reputation for a suspicious artifact, signer, hash, URL, domain, certificate, package, or vendor. Use when threat intelligence informs triage while privacy, stale data, false positives, and behavior limits stay explicit.
Scanned 9/5/2026
Install to Claude Code
npx -y skills add gaelic-ghost/socket --skill check-artifact-reputation --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Check Artifact Reputation?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/gaelic-ghost-check-artifact-reputation)More formats (shields.io, HTML) on the badges page.
---
name: check-artifact-reputation
description: Check reputation for a suspicious artifact, signer, hash, URL, domain, certificate, package, or vendor. Use when threat intelligence informs triage while privacy, stale data, false positives, and behavior limits stay explicit.
---
# Check Artifact Reputation
## Overview
Gather provenance and intelligence without treating popularity, valid signing, a clean lookup, or a vendor label as a safety verdict. Prefer local identity and vendor sources before sending data to third parties.
Read [references/reputation-evidence.md](references/reputation-evidence.md) for source ordering and interpretation.
## Workflow
1. Fix identity.
- Record artifact hashes, signer/certificate, exact version, source URL, domain, resolved destinations, and acquisition time.
2. Check local evidence.
- Inspect quarantine/provenance, signature/notarization, known installation records, local security detections, and expected vendor distribution paths.
3. Check authoritative sources.
- Prefer vendor advisories, release checksums/signatures, certificate status, official repositories, and current platform security sources.
- Date each lookup.
4. Decide whether external intelligence is appropriate.
- Explain whether the service receives only a hash/domain or may upload/retain the artifact.
- Obtain explicit approval before sending private artifacts, URLs, customer data, or unknown binaries.
5. Correlate results.
- Record detection names, engines/sources, first/last seen, submission context, prevalence, relations, and conflicting classifications.
- Distinguish “not present” from “known benign.”
6. Feed behavior analysis.
- Use reputation to prioritize static/dynamic checks, not replace them.
## Output
Return identity, sources/date, privacy decision, reputation observations, conflicts, interpretation limits, confidence effect, and next behavioral check.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!