deep-invade
Warn
Audited by Socket on Jul 31, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS/HIGH-RISK skill. Its behavior is internally consistent with its stated purpose, but that purpose is an offensive penetration-testing workflow for an AI agent, including SSRF to metadata/internal hosts, credential harvesting from logs/JS, active vuln scanning, and use of Collaborator/interactsh plus Tor. Provenance of named tools is mostly legitimate, so this is not confirmed malware, but it is a high-risk security skill that materially enables unauthorized exploitation and data exfiltration.
Confidence: 95%Severity: 94%
Audit Metadata