tm-security-review

Warn

Audited by Socket on Sep 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK but not malware. The skill is internally consistent with its stated purpose and shows no evident credential theft, remote installer abuse, or exfiltration. However, its purpose is to equip the agent with offensive security-review behavior, including exploit validation and runnable PoCs, which is inherently high risk for an AI agent even when framed as a legitimate audit workflow.

Confidence: 90%Severity: 81%
Audit Metadata
Analyzed At
Sep 18, 2026, 03:59 AM
Package URL
pkg:socket/skills-sh/security-phoenix-demo%2Fsecurity-skills-claude-code%2Ftm-security-review%2F@f1ef01bea80fb18269304f194b55f9b0803198d91dac9a0fc1e47fc79dbfe771
Security Audit — socket — tm-security-review