check-exploit
Warn
Audited by Socket on Aug 22, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS/HIGH-RISK vulnerable skill, not confirmed malware. Its stated purpose matches its behavior, but that purpose is to arm an AI agent with offensive exploit-discovery capability, and it additionally includes an unpinned third-party git-clone-and-run step (Pompem) that materially increases supply-chain risk.
Confidence: 89%Severity: 78%
Audit Metadata