qe-pentest-validation

Warn

Audited by Socket on Sep 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. The stated purpose matches the capabilities, so this is not deceptive malware, but it is an offensive-security skill that enables AI-driven exploitation against live systems. Safeguards are described, yet the footprint includes high-impact actions like reverse-shell proof, cookie theft PoC, metadata extraction, and credential-stuffing validation, plus delegation to other skills. No clear malicious exfiltration path is shown, but the capability itself is dangerous and disproportionate for general agent use.

Confidence: 89%Severity: 82%
Audit Metadata
Analyzed At
Sep 18, 2026, 06:16 PM
Package URL
pkg:socket/skills-sh/proffesor-for-testing%2Fagentic-qe%2Fqe-pentest-validation%2F@51f5d1b09f5ca4988f15aac8619fda3364a93013b0f51f5524712f40b51690fb
Security Audit — socket — qe-pentest-validation