dalfox
Warn
Audited by Socket on Sep 5, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s capabilities mostly match its stated purpose as an XSS scanner, but it equips an AI agent with offensive security functionality, arbitrary shell execution on findings, and third-party callback/webhook flows. The flagged patterns are largely documentation artifacts, not proof of malware, yet the overall footprint is high-risk and should be treated as a vulnerable security tool rather than a benign general-purpose helper.
Confidence: 88%Severity: 72%
Audit Metadata