defense-purple-team

Warn

Audited by Socket on Sep 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent as a purple-team methodology, but it equips an AI agent to run offensive-security emulation against live techniques. There is no direct evidence of malware, credential theft, or hidden data routing, yet the capability itself creates high operational risk and should be tightly sandboxed and approval-gated.

Confidence: 89%Severity: 72%
Audit Metadata
Analyzed At
Sep 20, 2026, 11:02 PM
Package URL
pkg:socket/skills-sh/noorqureshi%2Fsploitagent%2Fdefense-purple-team%2F@0b164bb88131c54b77e4422021cdf7c96a967e77bb9d01c2f6da1bf53165eeb5
Security Audit — socket — defense-purple-team