vulnerability-writeup

Warn

Audited by Socket on Jul 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent for vulnerability reporting, with no obvious malicious install path, credential harvesting, or third-party data routing. However, it materially equips the agent to perform exploitability analysis, build PoCs, run commands, and optionally access labs over SSH/VM, which makes it high-risk offensive-security functionality despite being framed as disclosure assistance.

Confidence: 88%Severity: 72%
Audit Metadata
Analyzed At
Jul 30, 2026, 04:23 AM
Package URL
pkg:socket/skills-sh/openai%2Fplugins%2Fvulnerability-writeup%2F@48178e309a9aac162179c053f4fb797e314e5f0a0bdc3b85a9f3bf0fe0a13558
Security Audit — socket — vulnerability-writeup