qa-chaos-monkey

Warn

Audited by Socket on May 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK but not malware: the skill is internally consistent for adversarial API QA and shows no supply-chain abuse or third-party credential routing, but it equips an AI agent with genuine offensive security testing behavior, local secret access, and autonomous live-request execution. Risk comes from capability class and agent permissions, not hidden exfiltration or deceptive installation.

Confidence: 89%Severity: 78%
Audit Metadata
Analyzed At
May 9, 2026, 08:19 PM
Package URL
pkg:socket/skills-sh/ravnhq%2Fai-toolkit%2Fqa-chaos-monkey%2F@df37653c7d7165ffe4a85838606280f1fb67bb99
Security Audit — socket — qa-chaos-monkey