strix-pentest
Warn
Audited by Socket on Aug 6, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally coherent for its stated purpose, but that purpose is to give an AI agent offensive security capability. The managed API endpoints are same-org and aligned, and the OSS CLI appears official/open-source, yet the curl|bash installer and credential forwarding to the CLI/LLM providers raise supply-chain and secret-handling risk. High overall risk comes mainly from autonomous pentesting functionality, not clear malware or deception.
Confidence: 90%Severity: 83%
Audit Metadata