one-gadget
Warn
Audited by Socket on Sep 5, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
This skill appears to be a legitimate wrapper/reference for a real upstream exploit-development tool, with normal package provenance and no sign of credential theft or covert exfiltration. However, its core function is to help an AI agent identify code-execution gadgets for exploitation, so it should be classified as high security risk but not malware.
Confidence: 92%Severity: 78%
Audit Metadata