web-app-security-audit

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is purpose-aligned, but its purpose is to give an AI agent offensive security testing capability with command execution against web targets. Install trust is mostly acceptable, with moderate supply-chain risk from external tooling and weaker verification for testssl.sh. No clear credential theft or exfiltration is present, so this is high-risk security tooling rather than confirmed malware.

Confidence: 89%Severity: 82%
Audit Metadata
Analyzed At
Apr 21, 2026, 03:24 PM
Package URL
pkg:socket/skills-sh/ahmedhamadto%2Fsoftware-forge%2Fweb-app-security-audit%2F@e4310991e64acb43d47b7636b9f1781fa2742b2a
Security Audit — socket — web-app-security-audit