nikto

Warn

Audited by Socket on Sep 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally consistent for authorized pentesting, but it grants an AI agent active web-vulnerability scanning capability and includes command-line credential use. Supply-chain concerns are limited because Nikto is an established upstream tool, yet the overall skill remains high-risk due to offensive security use and sensitive credential forwarding patterns.

Confidence: 89%Severity: 74%
Audit Metadata
Analyzed At
Sep 3, 2026, 02:39 AM
Package URL
pkg:socket/skills-sh/timsonner%2Fagent-skills%2Fnikto%2F@86e40da5c645bbf31005540f33a8d1bb562eeaee9afa79c4ab1912d78196db39
Security Audit — socket — nikto