performing-authenticated-scan-with-openvas

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill is internally coherent for OpenVAS/GVM authenticated scanning and uses mostly official Greenbone/Kali sources, so it is not strong evidence of malware. However, it grants an AI agent real offensive scanning capability, handles privileged credentials directly, reads a raw SSH key in an example, and supports scheduled scans; this makes it high security risk despite limited signs of malicious data exfiltration.

Confidence: 89%Severity: 76%
Audit Metadata
Analyzed At
Apr 21, 2026, 12:24 AM
Package URL
pkg:socket/skills-sh/mukul975%2Fanthropic-cybersecurity-skills%2Fperforming-authenticated-scan-with-openvas%2F@5ae6f4b99eece63b4466042e22606edd04a3ad30