security-audit
Warn
Audited by Socket on Aug 14, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally consistent and not overtly malicious, but it equips an AI agent with offensive security and penetration-testing capability. Install provenance appears legitimate, so the main concern is the high-risk capability itself and the transitive trust of the skills CLI, not credential theft or covert exfiltration.
Confidence: 89%Severity: 76%
Audit Metadata