vuln-scanner
Warn
Audited by Socket on Sep 6, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill is internally coherent for vulnerability research and disclosure, and its network destinations are official GitHub/Resend endpoints rather than clear exfiltration relays. However, it is a high-risk offensive-security workflow for an AI agent: it installs mutable third-party tooling, executes untrusted target code, scans external repos for exploitable flaws, and can autonomously contact maintainers or file reports/PRs. This is not confirmed malware, but it is a high-risk skill that exceeds a normal documentation/integration footprint.
Confidence: 88%Severity: 82%
Audit Metadata