attack-surface-analyzer

Warn

Audited by Socket on May 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's stated purpose is generic, but it grants broad shell and file-modification powers typical of an active security tool. There is no clear exfiltration or credential theft path, but the capability footprint is under-scoped and high risk for a vaguely defined pentesting-related skill.

Confidence: 85%Severity: 74%
Audit Metadata
Analyzed At
May 4, 2026, 02:31 PM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus-skills%2Fattack-surface-analyzer%2F@f246456ff5c1bf3e1eecf3607630e2fb6ab1cfca