sstimap

Warn

Audited by Socket on Sep 5, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is coherent with its stated purpose, but that purpose is offensive SSTI detection and exploitation for an AI agent, including remote command execution and shell access. Install trust is moderate rather than extreme because the repo is legitimate and public, but the unpinned personal-repo clone and offensive capability keep overall risk high.

Confidence: 93%Severity: 78%
Audit Metadata
Analyzed At
Sep 5, 2026, 10:45 PM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fsstimap%2F@40222222f88297a79fefb2b7060e83194262362ce3e4835f97121c8b48878ad7
Security Audit — socket — sstimap