penetration-testing-with-strix
Warn
Audited by Socket on Oct 4, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
BENIGN for stated purpose but HIGH RISK in operation: the skill is internally consistent with an autonomous pentesting tool, uses official Strix endpoints, and the flagged installer appears same-org rather than deceptive. The main risk is not misalignment but capability: it equips an AI agent to perform offensive security actions, optionally upload local source to the vendor cloud, and process untrusted target content with execution authority.
Confidence: 89%Severity: 81%
Audit Metadata