penetration-testing-with-strix

Warn

Audited by Socket on Aug 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is coherent with its stated purpose, and the installer/API endpoints appear same-org and official, but it grants an AI agent high-risk offensive security capabilities, uses a curl|bash installer, and can send sensitive scan context to Strix cloud. This is not confirmed malware, but it is a high-risk pentesting skill that should only be used with strict authorization and trust in the vendor.

Confidence: 90%Severity: 82%
Audit Metadata
Analyzed At
Aug 7, 2026, 06:31 PM
Package URL
pkg:socket/skills-sh/usestrix%2Fstrix%2Fpenetration-testing-with-strix%2F@4beaa585d5931a480e84a0905d9ab4f9b6f4306cca1774ea7b16cd4556845c91
Security Audit — socket — penetration-testing-with-strix