security-pen-testing
Warn
Audited by Socket on Sep 4, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill is internally consistent with its stated purpose, but that purpose is to equip an AI agent with offensive security capabilities, including exploit payloads, token handling, target probing, and potential secret discovery. Install provenance is mostly legitimate and same-org where referenced, so this is not confirmed malware; the main concern is the high-risk offensive scope and exfiltration-capable workflows rather than deceptive supply-chain behavior.
Confidence: 91%Severity: 84%
Audit Metadata