llm-security
Warn
Audited by Socket on Sep 14, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally coherent as an LLM red-team/security-testing skill, and its listed installs mostly match official registry distribution. The main risk is not hidden exfiltration but that it gives an AI agent offensive security capabilities, including prompt-injection, system-prompt extraction, and tool-abuse testing, which are high-risk even with an authorization gate. Supply-chain risk is moderate due to unpinned third-party tooling, but there is no evidence here of malware, credential harvesting, or deceptive data routing.
Confidence: 94%Severity: 74%
Audit Metadata