arjun
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The skill is internally consistent with its stated purpose, but that purpose is to equip an AI agent with offensive web-security testing workflows. Installation trust is relatively normal (PyPI, no curl|bash), yet the capability scope is high-risk because it enables authenticated scanning, passive recon, and direct handoff into exploit-oriented tools. Suspicious overall due to offensive-agent use, not because of hidden exfiltration or deceptive install behavior.
Confidence: 89%Severity: 78%
Audit Metadata