web3-audit

Warn

Audited by Socket on Aug 24, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent as a Web3 audit playbook, but it gives an AI agent offensive security capabilities for exploit discovery and PoC development against real DeFi targets. No clear credential theft, covert exfiltration, or malicious installer behavior is present, so this is high-risk enablement rather than confirmed malware.

Confidence: 91%Severity: 82%
Audit Metadata
Analyzed At
Aug 24, 2026, 11:03 PM
Package URL
pkg:socket/skills-sh/elementalsouls%2Fclaude-bughunter%2Fweb3-audit%2F@236d4a6f2211ecc2b467e3996a9ad09506386bc9198f5e158a6580e22a6d783c
Security Audit — socket — web3-audit