linux-exploit-suggester

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s behavior matches its stated exploit-suggester purpose, but that purpose is inherently offensive for an AI agent and the install methods are high-risk download-and-execute patterns. Same-org GitHub ownership suggests this is not confirmed malware, yet the unpinned raw-script execution and arbitrary attacker-host transfer workflow make it a high-risk security tool skill.

Confidence: 95%Severity: 86%
Audit Metadata
Analyzed At
Sep 15, 2026, 09:58 AM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Flinux-exploit-suggester%2F@12776268cba029670cc3679ae6a3631bd4ff67988b95384f67e44b9dc4d2ee5c
Security Audit — socket — linux-exploit-suggester