llm-risk-assess

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally aligned with its purpose, but that purpose is to equip an AI agent with offensive LLM security testing and red-team capabilities. There is no clear credential harvesting, exfiltration, or deceptive install path, so it is not malicious; however, the combination of Bash/WebFetch/Agent access and explicit attack techniques makes it a high-risk security skill.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Sep 15, 2026, 09:33 PM
Package URL
pkg:socket/skills-sh/owasp%2Fsecure-agent-playbook%2Fllm-risk-assess%2F@ac6b0259bf2bf235185b66fa24a81a62cbfa7f6449a33923130c7ab43aaafed2
Security Audit — socket — llm-risk-assess