badwhale-api-skill
Warn
Audited by Socket on Jun 5, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill is internally consistent with its stated purpose, but that purpose is an offensive security testing workflow with real-world external effects. Credential use is proportionate, yet data-flow integrity is weakened because the API base URL is arbitrary and not pinned to an official BadWhale domain. No strong malware indicators or stealth behavior are present, but the combination of offensive testing capability, credential forwarding, and remote action makes this a high-risk skill rather than a benign helper.
Confidence: 89%Severity: 78%
Audit Metadata