smuggler
Warn
Audited by Socket on Sep 5, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s behavior matches its stated purpose, but that purpose is to give an AI agent offensive web exploitation capability, including bulk request-smuggling scans against arbitrary hosts. Install trust is moderate rather than extreme: it uses a public GitHub source checkout, but from a personal account and with an extra dependency-install step not clearly confirmed by upstream docs. No credential harvesting or hidden exfiltration is evident, so this is not confirmed malware, but it is a high-risk security tool for agent use.
Confidence: 89%Severity: 78%
Audit Metadata