dotdotpwn

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is coherent with its stated purpose and shows no clear credential theft or covert exfiltration, but it equips an AI agent with offensive directory-traversal testing capabilities against network targets. Install trust is mostly acceptable via Kali apt; the GitHub/CPAN path is moderate supply-chain risk, not malware evidence.

Confidence: 92%Severity: 74%
Audit Metadata
Analyzed At
Sep 15, 2026, 09:59 AM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fdotdotpwn%2F@97723764377179099f4fae0b17870d903e8cf841ac23ec6ab42db2f71d2e6f95
Security Audit — socket — dotdotpwn