source-review-technique

Warn

Audited by Socket on Sep 5, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent and does not appear to steal data or execute hidden payloads, but it is a high-risk offensive security skill that equips an AI agent to perform vulnerability discovery. The scanner's command-injection and concealment signals look like false positives from documentation text, so this is not malware; the main risk is the skill's security-testing capability itself.

Confidence: 91%Severity: 72%
Audit Metadata
Analyzed At
Sep 5, 2026, 10:44 PM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fsource-review-technique%2F@64850685a198564b8b1bdfa1a28b3a493f0c49036c0ed08cecce8573e4914de0
Security Audit — socket — source-review-technique