ghost-proxy
Warn
Audited by Socket on Sep 29, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally coherent for a MITM proxy, but it gives an AI agent high-risk offensive traffic interception capability, stores full captured traffic locally, and uses a curl|bash installer without strong artifact verification. This looks like a legitimate same-org security tool rather than credential theft malware, but its operational footprint is inherently dangerous and should be treated as high risk.
Confidence: 83%Severity: 74%
Audit Metadata