dev-loop-security-auditor

Warn

Audited by Socket on Jul 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent as a security-auditing guide, but it grants an AI agent active offensive-security workflows including penetration-testing and DAST against user-specified targets. There is no clear malware or exfiltration behavior, yet the capability set is high-risk by design and should be treated as a vulnerable/offensive skill rather than a benign documentation-only helper.

Confidence: 86%Severity: 74%
Audit Metadata
Analyzed At
Jul 8, 2026, 12:21 PM
Package URL
pkg:socket/skills-sh/j4flmao%2Fagent-skills%2Fdev-loop-security-auditor%2F@4e80868a71275f82bd409417200409a5a945747bab4a087b4aeabf8f5475f380
Security Audit — socket — dev-loop-security-auditor