acidrain-security-testing-scripts

Warn

Audited by Socket on Aug 23, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s stated purpose matches its offensive capabilities, but it is still high risk because it equips an AI agent to perform web exploitation workflows, includes explicit cookie exfiltration examples, and relies on an unpinned third-party GitHub repo unrelated to the publisher. This looks more like a risky offensive-security skill than confirmed malware.

Confidence: 90%Severity: 81%
Audit Metadata
Analyzed At
Aug 23, 2026, 03:33 PM
Package URL
pkg:socket/skills-sh/aradotso%2Fsecurity-skills%2Facidrain-security-testing-scripts%2F@f816b8f68857bc70307f42140b7981b59eab912230fb4e607393513e046eef41
Security Audit — socket — acidrain-security-testing-scripts