pentest-ai-agents

Warn

Audited by Socket on May 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. Its capabilities are purpose-aligned for offensive security, so this is not deceptive in scope, but it intentionally enables an AI agent to perform exploit planning, phishing, credential capture, payload generation, and post-exploitation actions with real-world consequences. The same-org installer appears legitimate yet uses unpinned curl|bash. Overall this is not confirmed malware, but it is a high-risk offensive-security skill that should be treated as dangerous.

Confidence: 92%Severity: 93%
Audit Metadata
Analyzed At
May 18, 2026, 05:05 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Fsecurity-skills%2Fpentest-ai-agents%2F@fd4a1bca8d342919457176d99ddcc2c00712ad98
Security Audit — socket — pentest-ai-agents