mantis-reproduce

Warn

Audited by Socket on Jul 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent for vulnerability reproduction, but it grants an AI agent high-risk offensive security behavior by directing it to generate and execute exploit/crash PoCs, iterate on failures, and optionally parallelize attempts. Sandboxing constraints help, and there is no clear credential harvesting or third-party proxying, but this remains a high-risk exploit/testing skill rather than a benign general developer helper.

Confidence: 89%Severity: 84%
Audit Metadata
Analyzed At
Jul 13, 2026, 06:42 PM
Package URL
pkg:socket/skills-sh/google%2Fmantis%2Fmantis-reproduce%2F@bf6a93b26436dc239806efa1e181fe077abfa27e
Security Audit — socket — mantis-reproduce