penetration-testing-with-strix

Warn

Audited by Socket on Oct 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

BENIGN for stated purpose but HIGH RISK in operation: the skill is internally consistent with an autonomous pentesting tool, uses official Strix endpoints, and the flagged installer appears same-org rather than deceptive. The main risk is not misalignment but capability: it equips an AI agent to perform offensive security actions, optionally upload local source to the vendor cloud, and process untrusted target content with execution authority.

Confidence: 89%Severity: 81%
Audit Metadata
Analyzed At
Oct 4, 2026, 02:40 AM
Package URL
pkg:socket/skills-sh/usestrix%2Fstrix%2Fpenetration-testing-with-strix%2F@0ca1b8d590e6bb86cff568ecf3086ec5b6c0fbb689653d2b20ce8d73258478ef
Security Audit — socket — penetration-testing-with-strix