check-exploit

Warn

Audited by Socket on Aug 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK vulnerable skill, not confirmed malware. Its stated purpose matches its behavior, but that purpose is to arm an AI agent with offensive exploit-discovery capability, and it additionally includes an unpinned third-party git-clone-and-run step (Pompem) that materially increases supply-chain risk.

Confidence: 89%Severity: 78%
Audit Metadata
Analyzed At
Aug 22, 2026, 08:10 AM
Package URL
pkg:socket/skills-sh/rifteo%2Fskills%2Fcheck-exploit%2F@9d13400f93ab7c340c14be806fcabaa406e94ac6615235abffee4edc72462092
Security Audit — socket — check-exploit