testing-thick-clients
Warn
Audited by Socket on Aug 7, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill is internally coherent as a thick-client pentesting guide, but its actual footprint is intentionally offensive: extracting credentials from local stores/memory, intercepting traffic, bypassing trust controls, and leveraging recovered access against backend or database systems. There is little supply-chain concern in the text itself, yet the operational security risk is high because this equips an AI agent to conduct intrusive security testing on real infrastructure.
Confidence: 91%Severity: 82%
Audit Metadata