Web Application Security Testing

Warn

Audited by Socket on Mar 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally consistent with its stated purpose, but that purpose is to give an AI agent offensive web security testing capability. Installs are mostly from legitimate sources and there is no clear credential exfiltration, yet the skill enables high-risk pentesting and exploit-style actions against external targets without clear authorization safeguards.

Confidence: 90%Severity: 86%
Audit Metadata
Analyzed At
Mar 16, 2026, 07:54 PM
Package URL
pkg:socket/skills-sh/Masriyan%2FClaude-Code-CyberSecurity-Skill%2Fweb-application-security-testing%2F@38dd95d56bfcb34a2dc0d04cd231fad3d313e5e7