hexstrike-forge
Warn
Audited by Socket on Aug 22, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS/HIGH-RISK skill. Its stated purpose matches its capabilities, but that purpose is to give an AI agent structured penetration-testing behavior, including active scans, authenticated testing, and multi-target workflows. The repeated installation of additional skills adds transitive trust risk. No clear credential exfiltration or hidden data routing is shown, so this is not confirmed malware, but it is a high-risk offensive-capability skill.
Confidence: 90%Severity: 83%
Audit Metadata