pentestcode-ai-pentest-agent

Warn

Audited by Socket on Jul 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. Its stated purpose matches its offensive capabilities, but those capabilities are themselves dangerous for an AI agent: autonomous pentesting, credential spraying, exploitation, and post-exploitation. The raw GitHub curl|bash installer adds significant supply-chain risk, and the skill concentrates sensitive credentials/state for reuse.

Confidence: 93%Severity: 94%
Audit Metadata
Analyzed At
Jul 14, 2026, 09:25 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Fsecurity-skills%2Fpentestcode-ai-pentest-agent%2F@aa327e50bf0049a1596905d893e42014aab6ed9ae7586513e5959981eb6b665e
Security Audit — socket — pentestcode-ai-pentest-agent