pentest-playbook

Warn

Audited by Socket on Jul 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent as a pentest playbook, but its actual purpose is to equip an AI agent with offensive security workflow and to chain into additional attack skills. Install provenance for named tools is mostly legitimate, so this is not confirmed malware, but the capability set is high-risk and disproportionate for general agent use.

Confidence: 92%Severity: 88%
Audit Metadata
Analyzed At
Jul 31, 2026, 04:49 PM
Package URL
pkg:socket/skills-sh/uphiago%2Frecon-skills%2Fpentest-playbook%2F@eebbebbebce47b225ccb2e1e6d15b0564543b4c7fa54fac954e2861dfa3cc50a
Security Audit — socket — pentest-playbook