mimipenguin

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent with a credential-dumping tool, but that purpose itself gives an AI agent offensive secret-extraction capability, root access, and plaintext credential handling. There is no clear external exfiltration in the provided instructions, so this is high-risk security tooling rather than confirmed malware.

Confidence: 91%Severity: 90%
Audit Metadata
Analyzed At
Sep 15, 2026, 09:58 AM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fmimipenguin%2F@ed4961660a558b7f36a6780b11fd36c49ee9c523b06133f5dc3960421e03848f
Security Audit — socket — mimipenguin