offensive-bluetooth-classic

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is a penetration-testing playbook that equips an AI agent to perform offensive Bluetooth actions against external devices, including spoofing and eavesdropping. The main concrete technical issue is unpinned GitHub clone-and-execute of third-party tooling with some provenance ambiguity; there is no clear credential theft or exfiltration path, but this capability does not belong in a general AI agent skill without strong operator controls.

Confidence: 88%Severity: 74%
Audit Metadata
Analyzed At
Sep 15, 2026, 01:33 PM
Package URL
pkg:socket/skills-sh/snailsploit%2Fclaude-red%2Foffensive-bluetooth-classic%2F@418dc4716e5d41923a7db636472268fbcca213a671c94cc934bd22dffbab989f
Security Audit — socket — offensive-bluetooth-classic