performing-automated-malware-analysis-with-cape

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is internally aligned with malware-analysis use, and the sample client mainly talks to an expected CAPE API. However, it grants an AI agent high-risk offensive-security-adjacent capability, can upload samples to arbitrary CAPE endpoints, and references mutable same-org installer scripts without strong release verification. Not confirmed malware, but risky and should be tightly scoped to controlled local environments.

Confidence: 87%Severity: 69%
Audit Metadata
Analyzed At
Apr 10, 2026, 06:27 PM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Fperforming-automated-malware-analysis-with-cape%2F@c6014c0726d173bb2848f9b0aa6dee9410285cfa