security-audit

Warn

Audited by Socket on Mar 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The bundle is internally consistent as an offensive security workflow, but it is high risk because it explicitly enables AI-driven penetration testing and delegates to many unpinned downstream skills whose behavior and provenance are not established here. No direct credential theft or exfiltration is evident in this file alone, but the transitive trust chain and offensive scope make it unsafe to treat as benign.

Confidence: 87%Severity: 83%
Audit Metadata
Analyzed At
Mar 30, 2026, 06:23 AM
Package URL
pkg:socket/skills-sh/kursku%2Fskills%2Fsecurity-audit%2F@8e7d7c6608e68f9d6a9f1ac8632a1027d5ee2053
Security Audit — socket — security-audit