api-security-testing

Warn

Audited by Socket on Sep 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

HIGH RISK but not confirmed malware. The skill is internally consistent with an API pentesting purpose, and the Strix dependency appears same-org and officially documented. However, it gives an AI agent offensive security capability and forwards sensitive API tokens, including admin credentials, into an external CLI, so the overall risk is substantial even without clear deception or exfiltration.

Confidence: 91%Severity: 81%
Audit Metadata
Analyzed At
Sep 18, 2026, 04:16 AM
Package URL
pkg:socket/skills-sh/usestrix%2Fstrix%2Fapi-security-testing%2F@07cac73c27fe10a56e7018878cb8fa810c88a24a93a988f058998d112ea2e9ad
Security Audit — socket — api-security-testing