nuclei

Warn

Audited by Socket on Sep 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill is internally consistent and uses an official security tool for its stated pentest purpose, so there is no clear credential-harvesting or malware behavior. However, it equips an AI agent with offensive scanning capability and can forward auth tokens to an external CLI, making it high security risk despite low evidence of malicious intent.

Confidence: 90%Severity: 74%
Audit Metadata
Analyzed At
Sep 3, 2026, 02:39 AM
Package URL
pkg:socket/skills-sh/timsonner%2Fagent-skills%2Fnuclei%2F@5933ed45b313463003aafaf80e4f2c909c1707052a3796f8393cb26855ee2acd
Security Audit — socket — nuclei