pentest-agents-bug-bounty-framework

Warn

Audited by Socket on May 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is not obviously credential-stealing malware, but it is a high-risk offensive-security framework. Its actual footprint matches its stated purpose, yet that purpose itself gives an AI agent autonomous pentesting, exploit-chain construction, external-content ingestion, credentialed platform access, and report submission abilities that are dangerous and disproportionate for normal coding assistance.

Confidence: 93%Severity: 96%
Audit Metadata
Analyzed At
May 17, 2026, 07:29 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Fsecurity-skills%2Fpentest-agents-bug-bounty-framework%2F@8dd6971b6ea6aef9f1fc912ffdc24db854c90606
Security Audit — socket — pentest-agents-bug-bounty-framework