badwhale-api-skill

Warn

Audited by Socket on Jun 5, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill is internally consistent with its stated purpose, but that purpose is an offensive security testing workflow with real-world external effects. Credential use is proportionate, yet data-flow integrity is weakened because the API base URL is arbitrary and not pinned to an official BadWhale domain. No strong malware indicators or stealth behavior are present, but the combination of offensive testing capability, credential forwarding, and remote action makes this a high-risk skill rather than a benign helper.

Confidence: 89%Severity: 78%
Audit Metadata
Analyzed At
Jun 5, 2026, 08:49 AM
Package URL
pkg:socket/skills-sh/slowmist%2Fbadwhale-skills%2Fbadwhale-api-skill%2F@ad316c709c0ae25ddf30d2b2c09070458171fe64
Security Audit — socket — badwhale-api-skill