curl

Warn

Audited by Socket on Sep 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill is coherent as a curl guide for authorized pentesting, and it does not install third-party tooling or route credentials through an unexpected intermediary. But it materially equips an AI agent for offensive web testing, includes TLS-bypass usage, SSRF validation, and an unsafe executable download example over HTTP from a bare IP. This is not confirmed malware, but it is a high-risk dual-use skill whose capabilities exceed normal low-risk documentation.

Confidence: 91%Severity: 76%
Audit Metadata
Analyzed At
Sep 3, 2026, 02:40 AM
Package URL
pkg:socket/skills-sh/timsonner%2Fagent-skills%2Fcurl%2F@0c9849abc5d410d684abbd879ab66e0f2eed2921b2f0126b1a17cc82b247508a
Security Audit — socket — curl