offensive-dependency-confusion
Fail
Audited by Socket on Aug 27, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
SUSPICIOUS/HIGH-RISK. The skill is internally coherent as an offensive security methodology, but that purpose itself is dangerous for an AI agent: it teaches targeted supply-chain compromise, routes execution beacons to known exfiltration endpoints, and instructs autonomous public-registry publishing. Not confirmed malware by itself, but it materially enables real attacks and should be treated as a high-risk offensive skill.
Confidence: 97%Severity: 96%
Audit Metadata