find-security-vulnerabilities-in-code

Warn

Audited by Socket on Sep 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Suspicious/high-risk but not confirmed malware. The skill's capabilities mostly match its stated pentesting purpose, yet it equips an AI agent with live exploitation ability, writable code access, and external CLI execution; combined with mutable curl|bash installation, this makes it a high-risk security tool rather than a benign documentation helper.

Confidence: 85%Severity: 78%
Audit Metadata
Analyzed At
Sep 2, 2026, 02:07 AM
Package URL
pkg:socket/skills-sh/usestrix%2Fstrix%2Ffind-security-vulnerabilities-in-code%2F@28cbdca0f322af1bb70ba1de1dfe8217d821b1f6bced241d70e51814cb6b076c
Security Audit — socket — find-security-vulnerabilities-in-code