bore

Warn

Audited by Socket on Sep 5, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally consistent with bore’s stated purpose and uses official upstream distribution channels, so it does not look like a deceptive or malware-laced skill. However, it equips an AI agent with offensive tunneling patterns that can expose internal services, host payloads, receive reverse shells, and collect callbacks through public infrastructure, creating high real-world security risk despite coherent purpose.

Confidence: 90%Severity: 82%
Audit Metadata
Analyzed At
Sep 5, 2026, 10:45 PM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fbore%2F@38aa2715401544ac1a94ea912048328f11a89f0c19906d22db319241fabe98e6
Security Audit — socket — bore