managed-pentesting-with-strix

Warn

Audited by Socket on Aug 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: internally coherent as a managed pentesting skill, with official same-org API/data flows and no suspicious installer chain, but it grants an AI agent high-risk offensive security capabilities and forwards potentially sensitive scan credentials/context to a cloud service. Main risk is the nature of autonomous pentesting and external-action scope, not overt malware behavior.

Confidence: 91%Severity: 74%
Audit Metadata
Analyzed At
Aug 7, 2026, 06:31 PM
Package URL
pkg:socket/skills-sh/usestrix%2Fstrix%2Fmanaged-pentesting-with-strix%2F@a4cce92a4bd353035b705d7e6e9ee335818c038f0b6a1edc9af2e8361432ed3a
Security Audit — socket — managed-pentesting-with-strix