security-advisory-review

Warn

Audited by Socket on Jul 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent for vulnerability research, but it is a high-risk offensive-security skill because it instructs an AI agent to clone untrusted repos, install dependencies, generate exploit code, and execute it locally. Main concerns are exploit-tool enablement, command execution on untrusted content, and prompt-injection/supply-chain exposure rather than overt credential theft or exfiltration.

Confidence: 91%Severity: 84%
Audit Metadata
Analyzed At
Jul 22, 2026, 07:53 AM
Package URL
pkg:socket/skills-sh/nearform%2Fskills%2Fsecurity-advisory-review%2F@c46fbb91403c29a8dbd0f51554a7b57dd5fcb73bb5e7a7e25924b51e909010da
Security Audit — socket — security-advisory-review