vuln-scanner

Warn

Audited by Socket on Sep 6, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent for vulnerability research and disclosure, and its network destinations are official GitHub/Resend endpoints rather than clear exfiltration relays. However, it is a high-risk offensive-security workflow for an AI agent: it installs mutable third-party tooling, executes untrusted target code, scans external repos for exploitable flaws, and can autonomously contact maintainers or file reports/PRs. This is not confirmed malware, but it is a high-risk skill that exceeds a normal documentation/integration footprint.

Confidence: 88%Severity: 82%
Audit Metadata
Analyzed At
Sep 6, 2026, 01:18 AM
Package URL
pkg:socket/skills-sh/aeonfun%2Faeon%2Fvuln-scanner%2F@e06d84868bed598cd1acddf4b6f67c209464ba5857bf5690e634a95b4c512118
Security Audit — socket — vuln-scanner