autopentestx-automated-pentesting

Warn

Audited by Socket on May 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. Its stated purpose matches its capabilities, but those capabilities are offensive security functions that give an AI agent authority to scan, probe, and potentially exploit systems. The main inconsistency is install trust: ara.so publishes the skill while users are told to clone and run code from an unrelated personal GitHub repo. Data can also flow to arbitrary webhooks. This is not confirmed malware, but it is a high-risk AI agent skill with notable supply-chain and misuse concerns.

Confidence: 90%Severity: 86%
Audit Metadata
Analyzed At
May 17, 2026, 12:52 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Fsecurity-skills%2Fautopentestx-automated-pentesting%2F@feefd6069adb9af542badbcb25cb8d2c8654391e
Security Audit — socket — autopentestx-automated-pentesting