strix-pentest

Warn

Audited by Socket on Aug 6, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent for its stated purpose, but that purpose is to give an AI agent offensive security capability. The managed API endpoints are same-org and aligned, and the OSS CLI appears official/open-source, yet the curl|bash installer and credential forwarding to the CLI/LLM providers raise supply-chain and secret-handling risk. High overall risk comes mainly from autonomous pentesting functionality, not clear malware or deception.

Confidence: 90%Severity: 83%
Audit Metadata
Analyzed At
Aug 6, 2026, 02:19 PM
Package URL
pkg:socket/skills-sh/usestrix%2Fstrix%2Fstrix-pentest%2F@91235cdb1bb097072f8ecaf858541680648ebd0d6dd0d51537946e18fc3f8c96
Security Audit — socket — strix-pentest