automated-pentesting

Warn

Audited by Socket on Apr 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s behavior is coherent with its stated pentesting purpose, but that purpose is itself high risk for an AI agent: it enables automated offensive security actions against live targets. Tool provenance looks broadly legitimate, yet the skill lacks scoped authorization checks, target restrictions, and pinned installation guidance, so it should be treated as a high-risk offensive-security skill rather than benign automation.

Confidence: 91%Severity: 83%
Audit Metadata
Analyzed At
Apr 18, 2026, 05:57 PM
Package URL
pkg:socket/skills-sh/adryanmoldokkr32-pixel%2Fbionicbot-advanced-mechanics-security%2Fautomated-pentesting%2F@b308567421b37dbc398da65e7a01abf62c535744
Security Audit — socket — automated-pentesting