techstack-identification

Warn

Audited by Socket on May 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent as a passive tech-stack OSINT recon tool, but its stated use in pentest/CVE workflows gives an AI agent meaningful target-profiling capability. No credential harvesting, exfiltration, or installer abuse is evident, so this looks more like a high-risk security-recon skill than malware.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
May 13, 2026, 10:31 PM
Package URL
pkg:socket/skills-sh/transilienceai%2Fcommunitytools%2Ftechstack-identification%2F@edeb0c1348df761e93de6235e04a3e6315b6c230
Security Audit — socket — techstack-identification