shannon-ai-pentester

Warn

Audited by Socket on Sep 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill, not confirmed malware. The install path appears same-project and broadly legitimate, and the scanner’s .docker findings are benign documentation artifacts, but the skill’s core function is autonomous offensive security: reading source code, using credentials, and executing live exploits against running targets. That makes the security risk high by scope and real-world action, even though publisher/tool alignment is mostly coherent.

Confidence: 91%Severity: 78%
Audit Metadata
Analyzed At
Sep 12, 2026, 08:25 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Ftrending-skills%2Fshannon-ai-pentester%2F@92da82c4ce7c6f7c43159759d3ab1f8b77ff204c63cd28805dc0a4ce3d59dcca
Security Audit — socket — shannon-ai-pentester