penetration-testing-expert

Warn

Audited by Socket on Sep 11, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

The skill is coherent with its stated purpose, but that purpose is to provide offensive security capability to an AI agent. There are no clear credential-harvesting, covert exfiltration, or suspicious installer behaviors in the provided content, so this is not confirmed malware; however, the exploit, scanning, and payload-generation guidance makes it a high-risk skill for misuse.

Confidence: 87%Severity: 74%
AnomalyLOW
references/EXAMPLES.md

The supplied content is penetration-testing reference material rather than a concealed supply-chain attack. It performs network scanning, vulnerability probing, sensitive-data pattern detection, and includes explicit Metasploit exploitation and reverse-payload generation examples. Those capabilities are dangerous if used without authorization, and the Burp extension can disclose discovered secrets through local output, but the fragment shows no malware indicators or unauthorized exfiltration. It should be restricted to authorized testing environments and sensitive findings should be redacted.

Confidence: 98%Severity: 58%
Audit Metadata
Analyzed At
Sep 11, 2026, 05:15 AM
Package URL
pkg:socket/skills-sh/personamanagmentlayer%2Fpcl%2Fpenetration-testing-expert%2F@8d4458079e226f0305cca4724b8057c8d5c5645fa68dc58df5faaede2434c5ff
Security Audit — socket — penetration-testing-expert