security-engineer

Warn

Audited by Socket on May 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s core behavior is mostly aligned with a security-audit purpose and data stays within the local repo, but it equips the agent with offensive security review and penetration-testing capabilities, plus broad autonomous write access for remediation. There is no evident credential harvesting, third-party proxying, or malicious exfiltration path in this fragment, so this is not confirmed malware; however, as an AI agent skill it is high-risk because it enables security scanning/attack-style workflows and substantial autonomous code modification.

Confidence: 90%Severity: 78%
Audit Metadata
Analyzed At
May 1, 2026, 08:05 AM
Package URL
pkg:socket/skills-sh/buiphucminhtam%2Fforgewright%2Fsecurity-engineer%2F@b4678ec7b7fe292da8abf2508ff56c6302f99c86
Security Audit — socket — security-engineer