smuggler

Warn

Audited by Socket on Sep 5, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s behavior matches its stated purpose, but that purpose is to give an AI agent offensive web exploitation capability, including bulk request-smuggling scans against arbitrary hosts. Install trust is moderate rather than extreme: it uses a public GitHub source checkout, but from a personal account and with an extra dependency-install step not clearly confirmed by upstream docs. No credential harvesting or hidden exfiltration is evident, so this is not confirmed malware, but it is a high-risk security tool for agent use.

Confidence: 89%Severity: 78%
Audit Metadata
Analyzed At
Sep 5, 2026, 10:45 PM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fsmuggler%2F@a3a33b86925a4f28938bce28c52e8f7b31a1e8d65866a2364dbac8fc07935194
Security Audit — socket — smuggler