web-security-audit

Warn

Audited by Socket on Aug 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent and not overtly malicious, but it grants an AI agent offensive security capabilities against external systems. Main risk comes from enabling pentest/scanning behavior and from untrusted target content influencing an agent that may also execute tools or take actions.

Confidence: 89%Severity: 81%
Audit Metadata
Analyzed At
Aug 27, 2026, 11:51 AM
Package URL
pkg:socket/skills-sh/jce-joshhh77%2Fjce-opencode-tools%2Fweb-security-audit%2F@9308e03f85fa53710f45992986cd528e8206757a65653fe451b33e415e42dce6
Security Audit — socket — web-security-audit