server-security-scan

Warn

Audited by Socket on May 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. Its stated purpose matches its behavior, but it gives an AI agent meaningful offensive security and internal audit capabilities, including remote scanning, SSH-based enumeration, and reading sensitive authentication files. There is no clear malware or covert exfiltration, yet the operational risk is high because the skill can be misused against unauthorized targets and the authorization check is only procedural.

Confidence: 92%Severity: 84%
Audit Metadata
Analyzed At
May 19, 2026, 09:45 AM
Package URL
pkg:socket/skills-sh/tommasinigiovanni%2Fsecurity-skills%2Fserver-security-scan%2F@3a413aa455bb2d15d85183d5dadc64d83e362a72
Security Audit — socket — server-security-scan