bore
Warn
Audited by Socket on Sep 5, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill is internally consistent with bore’s stated purpose and uses official upstream distribution channels, so it does not look like a deceptive or malware-laced skill. However, it equips an AI agent with offensive tunneling patterns that can expose internal services, host payloads, receive reverse shells, and collect callbacks through public infrastructure, creating high real-world security risk despite coherent purpose.
Confidence: 90%Severity: 82%
Audit Metadata