password-auditor

Warn

Audited by Socket on Aug 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally aligned with its stated purpose, but that purpose is to give an AI agent offensive password-attack capabilities. No malware, exfiltration endpoint, or installer abuse is shown, yet the attack-oriented scope and lack of guardrails make it high security risk.

Confidence: 89%Severity: 78%
Audit Metadata
Analyzed At
Aug 8, 2026, 11:03 AM
Package URL
pkg:socket/skills-sh/alizafarbati%2Fopencode-agents-mcp%2Fpassword-auditor%2F@69cab374215766d3a48c4d4ca9df95d34003d512c098e39676db56d1861b1298
Security Audit — socket — password-auditor