security-auditor
Warn
Audited by Socket on May 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill is purpose-aligned as a security auditing tool and shows no external installer or obvious exfiltration path, but it grants an AI agent high-risk offensive security capability, including exploit PoC generation, while processing untrusted repository content with Bash and Write access. This is not confirmed malware, but it is a high-risk security skill that could be misused or prompt-injected.
Confidence: 90%Severity: 79%
Audit Metadata