testssl-sh

Warn

Audited by Socket on Sep 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent and does not show credential theft or hidden exfiltration, but it grants an AI agent active security-scanning capability against external hosts. Supply-chain risk is modest because the referenced tool appears to be an official upstream project, yet the agent-use case remains high risk due to offensive network probing potential.

Confidence: 90%Severity: 74%
Audit Metadata
Analyzed At
Sep 3, 2026, 02:39 AM
Package URL
pkg:socket/skills-sh/timsonner%2Fagent-skills%2Ftestssl-sh%2F@87be5665d66093d4beac44446d671bbe6ea62c8d4f53cd8aaad3cee292afcc65
Security Audit — socket — testssl-sh