owasp-top-10-testing
Warn
Audited by Socket on Aug 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill is internally aligned with its stated purpose, but that purpose is to give an AI agent offensive security capabilities and route test credentials and scan activity through an external CLI/platform. Install provenance looks same-org and not overtly malicious, yet the autonomous exploit behavior, credential forwarding, and transitive skill expansion make this a high-risk security skill.
Confidence: 90%Severity: 84%
Audit Metadata