autopentestx-automated-pentesting

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s offensive scanning/exploitation scope matches its stated purpose, but it installs and relies on an unrelated third-party pentesting repo rather than the publisher’s own verified distribution. Root-required scanning, arbitrary target interaction, optional Metasploit exploit execution, and optional webhook export create high security risk for an AI agent skill, though there is no confirmed credential theft or malware behavior in the provided content.

Confidence: 89%Severity: 78%
Audit Metadata
Analyzed At
Sep 15, 2026, 09:48 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Fsecurity-skills%2Fautopentestx-automated-pentesting%2F@6245340bf71380beca16836cb20f14f66b6fd78dfd99836bb52e36413229b8ca
Security Audit — socket — autopentestx-automated-pentesting