purple-team-automation

Warn

Audited by Socket on Aug 26, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s behavior is coherent with its stated purple-team purpose, but that purpose itself grants an AI agent high-risk offensive security and command-execution capability. No clear malware or credential-stealing behavior is shown, yet the ability to run adversary emulation frameworks and custom scripts makes it a high-risk security skill that should not be treated as benign.

Confidence: 88%Severity: 81%
Audit Metadata
Analyzed At
Aug 26, 2026, 09:21 PM
Package URL
pkg:socket/skills-sh/masriyan%2Fgemini-security-skills%2Fpurple-team-automation%2F@6975b5fd9747662de5b53694e9ca8e43dbd0fe1c340a85a174844a02b4ee7063
Security Audit — socket — purple-team-automation