kiterunner
Warn
Audited by Socket on Apr 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The install source is relatively coherent and same-org, but the skill’s core function is to give an AI agent offensive API discovery/brute-forcing capability with optional authenticated requests and replay against external systems. That makes it high security risk as an AI-agent skill, though not confirmed malware or credential theft.
Confidence: 90%Severity: 82%
Audit Metadata