winafl

Warn

Audited by Socket on Sep 5, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent and uses official-looking sources, so there is little sign of credential theft or deceptive supply-chain behavior. However, it equips the agent with high-risk offensive security capabilities for fuzzing and instrumenting Windows binaries, including attach mode and custom DLL workflows, which makes the overall skill high risk despite benign provenance.

Confidence: 94%Severity: 78%
Audit Metadata
Analyzed At
Sep 5, 2026, 10:44 PM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fwinafl%2F@40ce0167d5ce3bd7f137376766dde3c63ac1e6178353ccdf44edca22d6d609bb
Security Audit — socket — winafl