api-security-testing
Warn
Audited by Socket on Sep 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
HIGH RISK but not confirmed malware. The skill is internally consistent with an API pentesting purpose, and the Strix dependency appears same-org and officially documented. However, it gives an AI agent offensive security capability and forwards sensitive API tokens, including admin credentials, into an external CLI, so the overall risk is substantial even without clear deception or exfiltration.
Confidence: 91%Severity: 81%
Audit Metadata