sast

Warn

Audited by Socket on May 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent as a SAST pipeline, but it grants an AI agent high-risk offensive security capabilities, executes untrusted repository code/tooling, and can autonomously move from analysis to exploit development. The main concern is not deception; it is the disproportionate operational risk of enabling agentic vuln research and exploit creation on arbitrary repos.

Confidence: 91%Severity: 89%
Audit Metadata
Analyzed At
May 10, 2026, 08:01 AM
Package URL
pkg:socket/skills-sh/H-mmer%2Fpentest-agents%2Fsast%2F@0c19b288a176589f8d1d3ae20c7fe602b9d9c06e
Security Audit — socket — sast