security-reviewer
Warn
Audited by Socket on Jul 29, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The skill is coherent with its stated purpose, but that purpose is itself high risk: it equips an AI agent to run security scans and potentially active penetration-testing actions with Bash access. Install trust is mostly acceptable because the named tools are official third-party security utilities, but scope and autonomy risk remain high because the skill cannot technically enforce authorization or prevent misuse against unintended targets.
Confidence: 90%Severity: 78%
Audit Metadata