security-pen-testing

Warn

Audited by Socket on Sep 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally consistent with its stated purpose, but that purpose is to equip an AI agent with offensive security capabilities, including exploit payloads, token handling, target probing, and potential secret discovery. Install provenance is mostly legitimate and same-org where referenced, so this is not confirmed malware; the main concern is the high-risk offensive scope and exfiltration-capable workflows rather than deceptive supply-chain behavior.

Confidence: 91%Severity: 84%
Audit Metadata
Analyzed At
Sep 4, 2026, 02:34 PM
Package URL
pkg:socket/skills-sh/iwanhe%2Fpandawa%2Fsecurity-pen-testing%2F@5f63be5cda772092d43501903d98eeb90d0649daa5fc443895393490901ba064
Security Audit — socket — security-pen-testing