burpsuite-project-parser

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose is coherent, and required access to Burp project files is proportionate, but the skill’s key parsing capability depends on a non-publisher third-party extension from a personal GitHub repo with limited artifact verification. This is mainly a supply-chain trust issue rather than evidence of malicious behavior or credential theft.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
Mar 29, 2026, 03:13 PM
Package URL
pkg:socket/skills-sh/paperclipai%2Fcompanies%2Fburpsuite-project-parser%2F@89a8b10f457aa9986dfcb3c98b34e97e15fffa42