agent-abuse-pentest

Warn

Audited by Socket on Jul 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is purpose-aligned and avoids real exfiltration, installs, and credential collection, but it is still a security/pentest skill that teaches an AI agent to probe prompt-injection and tool-misuse attack paths. The main risk comes from offensive testing capability, not malware or supply-chain behavior.

Confidence: 93%Severity: 58%
Audit Metadata
Analyzed At
Jul 1, 2026, 04:30 PM
Package URL
pkg:socket/skills-sh/rwcod%2Fmcp-remote-oauth-pentest-kit%2Fagent-abuse-pentest%2F@42aee9ccfcc708e654567bf23815d42d8b5a44ec3d5770d021dc97a5f3c070d9
Security Audit — socket — agent-abuse-pentest