WebAssessment
Warn
Audited by Socket on Mar 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill is internally aligned to offensive web security work, but that purpose itself grants an AI agent high-risk exploit and scanning capabilities. The biggest concerns are offensive-security enablement, autonomous actions against external targets, indirect prompt injection from untrusted web content, and an unrelated mandatory localhost notification plus unpinned local-script trust.
Confidence: 89%Severity: 86%
Audit Metadata