find-security-vulnerabilities-in-code

Warn

Audited by Socket on Aug 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Suspicious/high-risk but not confirmed malware. The skill's capabilities mostly match its stated pentesting purpose, yet it equips an AI agent with live exploitation ability, writable code access, and external CLI execution; combined with mutable curl|bash installation, this makes it a high-risk security tool rather than a benign documentation helper.

Confidence: 85%Severity: 78%
Audit Metadata
Analyzed At
Aug 20, 2026, 11:39 PM
Package URL
pkg:socket/skills-sh/usestrix%2Fstrix%2Ffind-security-vulnerabilities-in-code%2F@a18910754ee5a8536472fa5650dd6f5bf25cfa7c54a37485ffe98d0b1018e31b
Security Audit — socket — find-security-vulnerabilities-in-code