testing-thick-clients

Warn

Audited by Socket on Aug 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent as a thick-client pentesting guide, but its actual footprint is intentionally offensive: extracting credentials from local stores/memory, intercepting traffic, bypassing trust controls, and leveraging recovered access against backend or database systems. There is little supply-chain concern in the text itself, yet the operational security risk is high because this equips an AI agent to conduct intrusive security testing on real infrastructure.

Confidence: 91%Severity: 82%
Audit Metadata
Analyzed At
Aug 7, 2026, 11:29 AM
Package URL
pkg:socket/skills-sh/trilwu%2Fsecskills%2Ftesting-thick-clients%2F@c59a583729d31922f6a40d5fba95bdc67eddec4657e71b997d8104213998ba68
Security Audit — socket — testing-thick-clients