chain
Warn
Audited by Socket on May 10, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill is internally consistent, but its purpose is to help an AI agent build exploit chains, which is a high-risk offensive capability. Install trust is mostly acceptable because `uv` is official and the skill does not fetch remote binaries, but the workflow still combines local code execution, optional external research ingestion, and delegated exploit reasoning in a way that poses substantial security risk.
Confidence: 91%Severity: 81%
Audit Metadata