penetration-testing-expert
Audited by Socket on Sep 11, 2026
2 alerts found:
SecurityAnomalyThe skill is coherent with its stated purpose, but that purpose is to provide offensive security capability to an AI agent. There are no clear credential-harvesting, covert exfiltration, or suspicious installer behaviors in the provided content, so this is not confirmed malware; however, the exploit, scanning, and payload-generation guidance makes it a high-risk skill for misuse.
The supplied content is penetration-testing reference material rather than a concealed supply-chain attack. It performs network scanning, vulnerability probing, sensitive-data pattern detection, and includes explicit Metasploit exploitation and reverse-payload generation examples. Those capabilities are dangerous if used without authorization, and the Burp extension can disclose discovered secrets through local output, but the fragment shows no malware indicators or unauthorized exfiltration. It should be restricted to authorized testing environments and sensitive findings should be redacted.