automated-pentesting
Warn
Audited by Socket on Apr 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s behavior is coherent with its stated pentesting purpose, but that purpose is itself high risk for an AI agent: it enables automated offensive security actions against live targets. Tool provenance looks broadly legitimate, yet the skill lacks scoped authorization checks, target restrictions, and pinned installation guidance, so it should be treated as a high-risk offensive-security skill rather than benign automation.
Confidence: 91%Severity: 83%
Audit Metadata