katana
Warn
Audited by Socket on Sep 5, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill is internally consistent and uses official same-org tooling, so it is not malware-like or a deceptive credential harvester. However, it equips an AI agent with offensive web reconnaissance and authenticated crawling capabilities, including passing live tokens and chaining into vulnerability scanning, which makes it high security risk despite low evidence of malicious intent.
Confidence: 91%Severity: 78%
Audit Metadata