vulnerability-writeup
Warn
Audited by Socket on Jul 30, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill is internally coherent for vulnerability reporting, with no obvious malicious install path, credential harvesting, or third-party data routing. However, it materially equips the agent to perform exploitability analysis, build PoCs, run commands, and optionally access labs over SSH/VM, which makes it high-risk offensive-security functionality despite being framed as disclosure assistance.
Confidence: 88%Severity: 72%
Audit Metadata