php-audit-pipeline

Warn

Audited by Socket on Mar 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK but not confirmed malicious. The skill is internally coherent as a PHP security-audit orchestrator and shows no credential harvesting, external exfiltration, or dubious installer behavior. However, it grants an AI agent substantial offensive security analysis capability, including exploit-class coverage and PoC generation, which makes the overall skill high risk under the AI-agent exploit-tooling policy.

Confidence: 90%Severity: 83%
Audit Metadata
Analyzed At
Mar 25, 2026, 02:35 AM
Package URL
pkg:socket/skills-sh/0xShe%2FPHP-Code-Audit-Skill%2Fphp-audit-pipeline%2F@cd2db99942c97989f469d2bb9d15f010df6dcf6b
Security Audit — socket — php-audit-pipeline