php-cmd-audit

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Suspicious but not malicious. The skill is internally consistent and does not show credential theft, exfiltration, remote installs, or hidden execution, but it explicitly enables an AI agent to perform command-injection vulnerability discovery and exploitation workflow, making it a high-risk security-audit/offensive capability.

Confidence: 92%Severity: 74%
Audit Metadata
Analyzed At
Sep 17, 2026, 01:00 AM
Package URL
pkg:socket/skills-sh/0xshe%2Fphp-code-audit-skill%2Fphp-cmd-audit%2F@fd21c39f404063c74591e5a4ed7db135a4e34b3e175c811acd87f543c8555712
Security Audit — socket — php-cmd-audit