amass

Warn

Audited by Socket on Sep 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is coherent with its stated pentest reconnaissance purpose and references legitimate same-project tools, but it gives an AI agent offensive external discovery capability and may use local API credentials via Amass config. There is no strong evidence of malware, credential harvesting, or third-party interception; the main concern is high-risk security tooling and real-world scanning use.

Confidence: 89%Severity: 72%
Audit Metadata
Analyzed At
Sep 3, 2026, 02:39 AM
Package URL
pkg:socket/skills-sh/timsonner%2Fagent-skills%2Famass%2F@bced5dd7cc218081f9f4f64f26157c4a7e20937fddc5c2d7c0bc54a7d72da98e
Security Audit — socket — amass